Triparchi

Privacy Policy

Last updated 9 October 2026

Triparchi is a trip-planning app published by Jared Matthew Ong ("we", "us"). This policy explains what the app does with information when you use it.

The short version

Your account

Triparchi asks you to sign in with Apple or with Google when you first open it, and an account is required to use the app. We receive your name, your email address and, if the provider supplies one, a profile photo. If you sign in with Apple and use "Hide My Email", we only ever receive the relay address Apple gives us. If you set your own profile photo, it is uploaded to our servers and shown to the people in trips and lists you share.

Account backup

While you are signed in, every trip and list on your phone is copied to our servers (Supabase) under your account: for a trip, its name, city, dates, days, stops, times and notes; for a list, its name, description and places. That way they come back when you sign in on a new phone or reinstall the app. Your backup is private to your account; nobody else can see it unless you share the trip or list.

A backed-up trip or list is deleted from our servers when you delete it in the app, and all of them are deleted when you delete your account.

Some things stay only on your phone: your settings and home base, your Scan nearby history, your Ask Archie conversations, imports you have not finished, and your travel map, which is worked out on your phone from your own trips and lists.

Ask Archie (AI)

Ask Archie is an AI assistant inside the app. When you send Archie a message:

Importing places

Links, text and screenshots. When you import places from a link, pasted text or screenshots, our server sends that content to the same AI (Google's Gemini, through OpenRouter) to find the places in it, and then matches them to real places with Google Places. For a link to a web page, our server fetches the page first. Your name and email are not sent with it. We do not store your screenshots or pasted text. We keep the result (the places found) for up to 30 days, tied to your account, so opening the same import again is quick. A web page's result is kept for a few days and reused for anyone who imports the same page.

TikTok and Instagram posts. When you share a post to Triparchi:

  1. The share sheet sends the post's link to our server, along with your sign-in, so we know the request is yours.
  2. Our server asks ScrapeCreators, a third-party service, to fetch the post: the caption, the location tag, the creator's subtitles and handle, and the video (or the photos of a carousel). Only public posts can be read.
  3. The post is sent to the same AI to find the places it names. Your name, email and account are not sent with it.
  4. The places found are matched to real places with Google Places.

We keep the post's text (caption and subtitles), its location tag, the creator's handle and the places we found, stored against the post's link, so the next person who shares the same post gets the answer straight away. This copy is not linked to you. We do not store the video or the photos.

The import log. Each import is logged with your account ID, what was imported (the link, or a short code for text and screenshots) and whether it worked. We use that log to apply the import allowance per person and to keep costs in check. After 90 days the link is removed from an entry; entries for imports that worked are kept without it (your account ID, the date and the result) so the allowance can still be counted, and the rest are deleted. We delete them sooner if you ask us. If you close the share sheet before an import finishes, we remember that you are waiting so we can notify you, and forget it as soon as the import is done.

Sharing trips and lists

When you share a trip or a list, it is stored on our servers so the people you invite can open it in their app, and it stays in sync between you.

Activity

When someone changes a trip or list you share, the other members see it in the app: that person's first name and a summary of what changed (for example "Sam added Senso-ji to Day 2", or that someone joined, left or had their role changed). Activity is deleted after 90 days, when the trip or list is deleted, and, for you, when you leave it or are removed from it.

Notifications

Triparchi only sends notifications if you allow them when iOS asks: that an import is ready, and updates when someone joins or changes a trip or list you share, or changes your role. Updates include the trip or list name, the person's first name and the places involved.

To make this work we store your phone's Apple push token with your account, and notifications are delivered through Apple's Push Notification service. The token is removed when you sign out on that phone, or when Apple tells us it is no longer valid. You can turn every notification off in iOS Settings › Notifications › Triparchi, or only trip and list updates in the app's Settings.

Location

Triparchi asks for your location only while you are using the app, never in the background, and only when you use a feature that needs it, such as Scan nearby or showing where you are on the map.

You can decline location access and search for a city instead; the rest of the app works normally.

Places, photos and routes

When you look at a city or a place, our server gets the places, opening hours, ratings, reviews and photos from Google Places and Tripadvisor. Most place photos are loaded through our own photo server, so your phone does not contact Google for them. Walking and driving routes come from Mapbox, and public-transport times from Apple Maps, which receive the start and end points of each leg.

Analytics and crash reports

The app does not use your device's advertising identifier and does not track you across other apps or websites, so you will not see an App Tracking Transparency prompt.

Device identifier

The app creates a random identifier for your device and keeps it in the iPhone Keychain, so it can survive a reinstall. It is not your advertising ID or serial number. We use it to credit a creator when you import their template or redeem their code, and to apply limits that stop abuse, together with your IP address, which we use only for that. Once you sign in, it is tied to your account.

Feedback and city requests

If you send feedback from the app, we receive your message, the app version, the install identifier above and, only if you type one, your email address. If you ask us to add a city, we store the city you asked for.

Purchases

If you subscribe, the payment is handled by Apple. We never see your card details. We use RevenueCat to manage subscriptions: it receives your purchase history and subscription status, tied to your Triparchi account ID, so your subscription follows your account to a new phone. If a creator referred you, RevenueCat also records that creator's code. RevenueCat never receives your name or email.

On our website

Android waitlist

If you join the Android waitlist on our website, we store the email address you enter and your browser's user-agent string, only so we can email you when Triparchi for Android is available. Write to contact@triparchi.com to be removed.

Creator links

When you open an itinerary someone shared on triparchi.com, or a link that names a creator, our website remembers who shared it. This is kept in your browser's local storage, not in a cookie, and is deleted after 30 days. It is added to the App Store link so that, if you install Triparchi, we can credit the creator who shared the itinerary with you.

Meta pixel and ad measurement

We advertise Triparchi on Facebook and Instagram. To see which ads bring people to our website, the homepage and this page use Meta's pixel and Meta's Conversions API. They tell Meta when you view a page and when you tap an App Store button, along with your IP address, your browser's details (its user-agent string), the page address and Meta's own cookies on our site (_fbp, and _fbc if you came from a Meta ad). The Conversions API is the same tap sent from our server, so Meta still counts it if your browser blocks the pixel. Meta may connect this to a Facebook or Instagram account you are signed in to, as described in Meta's privacy policy. We use the results to compare our ads.

If you are in the UK, the European Union, the EEA or Switzerland, none of this happens until you choose Accept on the banner at the bottom of the page. Elsewhere it is on, and you can turn it off by choosing Decline. Your choice is kept in your browser's local storage. To make or change it, use Cookie settings at the bottom of the homepage or this page, or clear this site's data in your browser and choose again.

Who else is involved

Running the app means using a small number of third-party services. Each one receives only what it needs to do its job:

ServiceWhat it doesWhat it receives
SupabaseHosts our database, sign-in, file storage and the functions the app callsYour account; your backed-up trips and lists; shared trips and lists; profile photos you set; activity; push tokens; import and Archie usage logs; the city or area you are looking at; our own usage events
OpenRouter, and Google (Gemini)Runs Ask Archie; reads imports to find places; writes review summaries for placesYour Archie messages with the trip or list context and, if allowed, rough location; the links, text, screenshots and posts you import; public reviews of places. Never your name or email
ScrapeCreatorsFetches a TikTok or Instagram post you share to TriparchiThe post's link, from our server
Google PlacesSupplies places, ratings, reviews, photos and opening hours, and matches places found in importsSearch areas, place names and place identifiers, from our server
TripadvisorSupplies some places, reviews and photosSearch areas and place identifiers, from our server
MapboxDraws the map and calculates walking and driving routesMap coordinates and route start and end points
OpenStreetMap (Nominatim)Turns coordinates into a place name, and searches addressesThe coordinates or address text you are looking up
AppleSign in with Apple, push notifications, public-transport times and paymentsYour sign-in request; notifications and your push token; the start and end of a transit leg; your purchase
Google Sign-InSigns you in, if you choose GoogleYour sign-in request
PostHogProduct analytics and crash reportsUsage events and error reports tied to your random account ID, on servers in the United States
RevenueCatManages subscriptionsYour account ID, purchase history and subscription status, and a creator's code if one referred you
Meta (Facebook, Instagram)Measures which of our ads bring people to triparchi.com (website only)Views of the homepage and this page, and App Store button taps, with your IP address, browser details, the page address and Meta's cookies. In the UK, EU, EEA and Switzerland, only after you accept
CloudflareRuns triparchi.com and the shared-link pagesVisits to the website, including shared-link pages

We do not sell personal information to anyone. The app does not share it for advertising purposes; the only advertising use is the website's Meta pixel described in Meta pixel and ad measurement.

How long we keep things

Deleting your data, and your rights

Depending on where you live, you may have the right to see the information we hold about you, to correct it, to have it deleted, or to object to how we use it. Much of that is already in your hands:

For anything else, write to contact@triparchi.com and we will respond within 30 days.

Children

Triparchi is not directed at children under 13, and we do not knowingly collect information from them.

Changes

If we change this policy we will update the date at the top of this page. Material changes will be announced in the app before they take effect.

Contact

Jared Matthew Ong
contact@triparchi.com