Privacy Policy
Last updated 9 October 2026
Triparchi is a trip-planning app published by Jared Matthew Ong ("we", "us"). This policy explains what the app does with information when you use it.
The short version
- You sign in with Apple or Google. While you are signed in, your trips and lists are backed up to our servers so you don't lose them on a new phone.
- When you use Ask Archie (our AI assistant) or import places from a link, text, screenshots or a reel, what you send is read by an AI model run by Google (Gemini), reached through a service called OpenRouter.
- We measure how the app is used and collect crash reports, tied to a random account ID, not your name or email.
- We do not sell data. The app shows no ads and does not track you across other apps or websites. Our website uses a Meta pixel to measure our own ads, and asks first in the UK, EU and Switzerland (see Meta pixel and ad measurement).
Your account
Triparchi asks you to sign in with Apple or with Google when you first open it, and an account is required to use the app. We receive your name, your email address and, if the provider supplies one, a profile photo. If you sign in with Apple and use "Hide My Email", we only ever receive the relay address Apple gives us. If you set your own profile photo, it is uploaded to our servers and shown to the people in trips and lists you share.
Account backup
While you are signed in, every trip and list on your phone is copied to our servers (Supabase) under your account: for a trip, its name, city, dates, days, stops, times and notes; for a list, its name, description and places. That way they come back when you sign in on a new phone or reinstall the app. Your backup is private to your account; nobody else can see it unless you share the trip or list.
A backed-up trip or list is deleted from our servers when you delete it in the app, and all of them are deleted when you delete your account.
Some things stay only on your phone: your settings and home base, your Scan nearby history, your Ask Archie conversations, imports you have not finished, and your travel map, which is worked out on your phone from your own trips and lists.
Ask Archie (AI)
Ask Archie is an AI assistant inside the app. When you send Archie a message:
- Our server sends your message to an AI model (Google's Gemini, through OpenRouter) to write the answer. With it go the parts of your trip or list that Archie needs, such as the city, dates, days, stops, notes and places, plus your last few messages in that conversation.
- If you have already allowed location access, your rough location (rounded to about a kilometre) is sent too. Archie never asks for location itself. Your name and email are not sent.
- To answer, Archie may look up places with Google Places and search the web.
- We ask the AI providers not to keep or train on what we send, for Archie and for imports.
- We do not keep your messages on our servers. We log only that a message was sent, its cost and whether it worked, to count your allowance. Your conversations are kept on your phone.
Importing places
Links, text and screenshots. When you import places from a link, pasted text or screenshots, our server sends that content to the same AI (Google's Gemini, through OpenRouter) to find the places in it, and then matches them to real places with Google Places. For a link to a web page, our server fetches the page first. Your name and email are not sent with it. We do not store your screenshots or pasted text. We keep the result (the places found) for up to 30 days, tied to your account, so opening the same import again is quick. A web page's result is kept for a few days and reused for anyone who imports the same page.
TikTok and Instagram posts. When you share a post to Triparchi:
- The share sheet sends the post's link to our server, along with your sign-in, so we know the request is yours.
- Our server asks ScrapeCreators, a third-party service, to fetch the post: the caption, the location tag, the creator's subtitles and handle, and the video (or the photos of a carousel). Only public posts can be read.
- The post is sent to the same AI to find the places it names. Your name, email and account are not sent with it.
- The places found are matched to real places with Google Places.
We keep the post's text (caption and subtitles), its location tag, the creator's handle and the places we found, stored against the post's link, so the next person who shares the same post gets the answer straight away. This copy is not linked to you. We do not store the video or the photos.
The import log. Each import is logged with your account ID, what was imported (the link, or a short code for text and screenshots) and whether it worked. We use that log to apply the import allowance per person and to keep costs in check. After 90 days the link is removed from an entry; entries for imports that worked are kept without it (your account ID, the date and the result) so the allowance can still be counted, and the rest are deleted. We delete them sooner if you ask us. If you close the share sheet before an import finishes, we remember that you are waiting so we can notify you, and forget it as soon as the import is done.
Sharing trips and lists
When you share a trip or a list, it is stored on our servers so the people you invite can open it in their app, and it stays in sync between you.
- Who can see it. Anyone who opens your link and signs in joins it, and links to trips and lists both let new people edit. To show someone a trip without letting them edit it, use Send a copy: they get a trip of their own, and nothing they change touches yours. You can turn the link off, or remove people, at any time. Anyone can leave a trip or list they have joined.
- Your name and photo. The other members see your name and profile photo next to what you added.
- The web page. Anyone holding the link, even without the app, can open a read-only page for it on triparchi.com. For a trip, that shows its name, city, dates, days, stops, times, hotel and day notes, with photos and maps, but never member names, stop notes or trip notes. For a list, it shows its name, description, the owner's first name and its places. Messaging apps such as iMessage, WhatsApp and Slack read a short preview of the same page to draw the card under the link.
- Public templates. Creators in our creator program can publish a trip as a public template. A template is visible to anyone at its triparchi.com link, with the creator's name and photo.
Activity
When someone changes a trip or list you share, the other members see it in the app: that person's first name and a summary of what changed (for example "Sam added Senso-ji to Day 2", or that someone joined, left or had their role changed). Activity is deleted after 90 days, when the trip or list is deleted, and, for you, when you leave it or are removed from it.
Notifications
Triparchi only sends notifications if you allow them when iOS asks: that an import is ready, and updates when someone joins or changes a trip or list you share, or changes your role. Updates include the trip or list name, the person's first name and the places involved.
To make this work we store your phone's Apple push token with your account, and notifications are delivered through Apple's Push Notification service. The token is removed when you sign out on that phone, or when Apple tells us it is no longer valid. You can turn every notification off in iOS Settings › Notifications › Triparchi, or only trip and list updates in the app's Settings.
Location
Triparchi asks for your location only while you are using the app, never in the background, and only when you use a feature that needs it, such as Scan nearby or showing where you are on the map.
- To work out which city a point is in, and when you search for an address or drop a pin, the coordinates or the address text go to OpenStreetMap's Nominatim service.
- When you move around a map in the app, the area on screen (rounded) is sent to our server to load the places in it.
- If you have allowed location, Ask Archie receives your rough location, as described above.
You can decline location access and search for a city instead; the rest of the app works normally.
Places, photos and routes
When you look at a city or a place, our server gets the places, opening hours, ratings, reviews and photos from Google Places and Tripadvisor. Most place photos are loaded through our own photo server, so your phone does not contact Google for them. Walking and driving routes come from Mapbox, and public-transport times from Apple Maps, which receive the start and end points of each leg.
Analytics and crash reports
The app does not use your device's advertising identifier and does not track you across other apps or websites, so you will not see an App Tracking Transparency prompt.
- PostHog, on servers in the United States, receives events such as which screens you open, that a trip was created, shared or exported, your answers to the onboarding questions, and what happened when a subscription offer was shown. When the app crashes or hits an error, it also receives an error report (the error and where in the app it happened). Once you sign in, these are tied to your Triparchi account ID, a random identifier. Your name and email are not sent. Automatic capture is off, so your keystrokes and screen contents are never sent.
- Our own server records a few events, such as which city was searched, with a random identifier generated when you install the app.
Device identifier
The app creates a random identifier for your device and keeps it in the iPhone Keychain, so it can survive a reinstall. It is not your advertising ID or serial number. We use it to credit a creator when you import their template or redeem their code, and to apply limits that stop abuse, together with your IP address, which we use only for that. Once you sign in, it is tied to your account.
Feedback and city requests
If you send feedback from the app, we receive your message, the app version, the install identifier above and, only if you type one, your email address. If you ask us to add a city, we store the city you asked for.
Purchases
If you subscribe, the payment is handled by Apple. We never see your card details. We use RevenueCat to manage subscriptions: it receives your purchase history and subscription status, tied to your Triparchi account ID, so your subscription follows your account to a new phone. If a creator referred you, RevenueCat also records that creator's code. RevenueCat never receives your name or email.
On our website
Android waitlist
If you join the Android waitlist on our website, we store the email address you enter and your browser's user-agent string, only so we can email you when Triparchi for Android is available. Write to contact@triparchi.com to be removed.
Creator links
When you open an itinerary someone shared on triparchi.com, or a link that names a creator, our website remembers who shared it. This is kept in your browser's local storage, not in a cookie, and is deleted after 30 days. It is added to the App Store link so that, if you install Triparchi, we can credit the creator who shared the itinerary with you.
Meta pixel and ad measurement
We advertise Triparchi on Facebook and Instagram. To see which ads bring people to our website, the
homepage and this page use Meta's pixel and Meta's Conversions API. They tell Meta when you view a page and when you
tap an App Store button, along with your IP address, your browser's details (its user-agent string), the
page address and Meta's own cookies on our site (_fbp, and _fbc if you came from a
Meta ad). The Conversions API is the same tap sent from our server, so Meta still counts it if your browser
blocks the pixel. Meta may connect this to a Facebook or Instagram account you are signed in to, as
described in Meta's privacy policy. We use the
results to compare our ads.
If you are in the UK, the European Union, the EEA or Switzerland, none of this happens until you choose Accept on the banner at the bottom of the page. Elsewhere it is on, and you can turn it off by choosing Decline. Your choice is kept in your browser's local storage. To make or change it, use Cookie settings at the bottom of the homepage or this page, or clear this site's data in your browser and choose again.
Who else is involved
Running the app means using a small number of third-party services. Each one receives only what it needs to do its job:
| Service | What it does | What it receives |
|---|---|---|
| Supabase | Hosts our database, sign-in, file storage and the functions the app calls | Your account; your backed-up trips and lists; shared trips and lists; profile photos you set; activity; push tokens; import and Archie usage logs; the city or area you are looking at; our own usage events |
| OpenRouter, and Google (Gemini) | Runs Ask Archie; reads imports to find places; writes review summaries for places | Your Archie messages with the trip or list context and, if allowed, rough location; the links, text, screenshots and posts you import; public reviews of places. Never your name or email |
| ScrapeCreators | Fetches a TikTok or Instagram post you share to Triparchi | The post's link, from our server |
| Google Places | Supplies places, ratings, reviews, photos and opening hours, and matches places found in imports | Search areas, place names and place identifiers, from our server |
| Tripadvisor | Supplies some places, reviews and photos | Search areas and place identifiers, from our server |
| Mapbox | Draws the map and calculates walking and driving routes | Map coordinates and route start and end points |
| OpenStreetMap (Nominatim) | Turns coordinates into a place name, and searches addresses | The coordinates or address text you are looking up |
| Apple | Sign in with Apple, push notifications, public-transport times and payments | Your sign-in request; notifications and your push token; the start and end of a transit leg; your purchase |
| Google Sign-In | Signs you in, if you choose Google | Your sign-in request |
| PostHog | Product analytics and crash reports | Usage events and error reports tied to your random account ID, on servers in the United States |
| RevenueCat | Manages subscriptions | Your account ID, purchase history and subscription status, and a creator's code if one referred you |
| Meta (Facebook, Instagram) | Measures which of our ads bring people to triparchi.com (website only) | Views of the homepage and this page, and App Store button taps, with your IP address, browser details, the page address and Meta's cookies. In the UK, EU, EEA and Switzerland, only after you accept |
| Cloudflare | Runs triparchi.com and the shared-link pages | Visits to the website, including shared-link pages |
We do not sell personal information to anyone. The app does not share it for advertising purposes; the only advertising use is the website's Meta pixel described in Meta pixel and ad measurement.
How long we keep things
- Your account and backup: for as long as your account exists. A trip or list you delete is removed from the backup.
- Shared trips and lists: until the owner deletes them. Turning a link off stops new people joining; it does not remove people who already have access.
- Activity: 90 days.
- Push tokens: until you sign out on that phone, or Apple reports the token is no longer valid.
- Imports: a post's text and the places found are kept, not linked to you. Results of your own text and screenshot imports, up to 30 days. The import log, as described above.
- Archie usage log: 400 days, except the entries that count your 5 messages without Pro, which are kept so the allowance does not refill. It holds no message text.
- Our own usage events: 24 months, then deleted.
- Android waitlist emails: until we have emailed you about the Android launch, or you ask us to remove it.
Deleting your data, and your rights
Depending on where you live, you may have the right to see the information we hold about you, to correct it, to have it deleted, or to object to how we use it. Much of that is already in your hands:
- Delete your account in the app: Settings › Delete account. That erases your account, your name, email and profile photo, and your backed-up trips and lists. Trips still saved on your phone stay there until you delete the app.
- Leave a shared trip or list, or, if you own it, turn its link off, remove people or delete it.
- Turn notifications off in iOS Settings, or trip and list updates in the app.
For anything else, write to contact@triparchi.com and we will respond within 30 days.
Children
Triparchi is not directed at children under 13, and we do not knowingly collect information from them.
Changes
If we change this policy we will update the date at the top of this page. Material changes will be announced in the app before they take effect.
Contact
Jared Matthew Ong
contact@triparchi.com