YesTrip

Privacy policy

Stand: October 2026

The German version of this privacy policy is the binding one. This English version is provided for convenience.

In short

1. Controller

John Henry Herzel – YesTrip
c/o flexdienst – #20713, Kurt-Schumacher-Straße 74
67663 Kaiserslautern
Germany
E-mail: contact@yestrip.app

This policy applies to the website yestrip.app ("landing page"), the web app at app.yestrip.app and the Android app "YesTrip" (together "YesTrip").

2. Data protection officer

We are not legally required to appoint a data protection officer (fewer than 20 people regularly process personal data, § 38 BDSG). For data protection questions, write to the e-mail address above.

3. Overview: where your data is

DataWhere
Trips (places, dates, plan items, notes)device and your account on our server
Travel profile (preferences you stated)device and your account on our server
Travel passport (visited countries, cities, flights)device and your account on our server
E-mail address, display nameour server
AI credits used per month (one number)our server
Flight price alerts (route, dates, highest price, price history)our server
AI chatyour device only (sent to Anthropic when you use the AI, see section 7) – never in your account
Tickets, photos, cover imagesyour device only (tickets and receipt photos you explicitly share: also on our server, only for the trip's members)
Settings (language, photos on/off etc.)your device only

If our server cannot be reached (e.g. offline on a plane), the app keeps working with the data on your device and syncs as soon as there is a connection again.

The "travel passport" in YesTrip is a collection of the places you visited and flights you took. It contains no identity document data.

4. Storage on your device

YesTrip stores your content in the local storage of your browser or the app (localStorage and IndexedDB), so the app is fast and also works offline. We have no access to this device storage; what is additionally kept in your account is described in section 6. You can delete it at any time by deleting the content in the app, clearing the site data in your browser or uninstalling the app.

Access to device storage is strictly necessary for the function you requested and is therefore allowed without consent (§ 25 (2) no. 2 TDDDG). The legal basis for the processing is Art. 6 (1) (b) GDPR (providing the app you want to use).

5. Providing the website and app, server logs

When you open the landing page or the web app, or when the app contacts our server (AI, partner search, account), our server processes technically necessary data: IP address, date and time, requested address, amount of data transferred, browser or app identifier (user agent) and status code.

Hosting: our server is run by Hostinger International Ltd., 61 Lordou Vironos str., 6023 Larnaca, Cyprus, data centre in Düsseldorf, Germany. We have a data processing agreement with Hostinger under Art. 28 GDPR (Hostinger's Data Processing Addendum, part of its terms).

Backups: the database with the accounts is backed up every night. The backups are kept only on our own server at Hostinger (see above); we do not use any other backup provider. We keep each backup for 7 days, after which it is deleted automatically. Legal basis: Art. 6 (1) (f) GDPR (protection against data loss).

The landing page loads no content from third parties. Fonts are served from our own server.

Contact by e-mail

If you write to contact@yestrip.app, we process your e-mail address, your name (if given) and the content of your message to reply to you. The mailbox is hosted by Hostinger (see above, data processing agreement under Art. 28 GDPR). Legal basis: Art. 6 (1) (b) GDPR if it concerns your account or the use of YesTrip, otherwise Art. 6 (1) (f) GDPR (answering your request). We delete the e-mails once the request has been dealt with, at the latest after 12 months, unless statutory retention obligations require otherwise.

6. Account

You need an account to use YesTrip. You sign in with your e-mail address and a code we send you. With the account your trips are available on all your devices, you can share them with friends, and we can limit AI usage fairly (section 7).

While you are signed in, the app syncs your trips, travel profile and travel passport with your account automatically. On your first sign-in, trips that were only on your device are moved into your account. Our server is located in the EU (see section 5).

What we store:

What we do not store: tickets, photos, cover images and your AI chat (exception: tickets and receipt photos you explicitly share with a shared trip, see "Planning together"). These stay on your device (for chat messages sent when you use the AI, see section 7). There are no passwords – you sign in with a code sent by e-mail.

Please do not enter data in trips and notes that does not belong there (e.g. ID or credit card numbers). Trips are stored in your account on our server.

Statistics on accounts and their contents

When you sign in, we derive the country from your IP address once and store only the country code (e.g. "DE") with your account – we do not store the IP address itself. We also store the day you last used YesTrip and when a trip was first saved.

For our product statistics we evaluate the contents of accounts – trips (destination, dates, trip style, group size, expenses), travel profile, passport and wish list – in summarised form only, for example "average cost per day in Portugal" or "most common destinations of accounts from Austria". We see no information about individual people, no e-mail addresses, names or free text; profile entries appear only when at least three accounts gave the same entry.

Operation, support and abuse prevention

As the operator we can view the data of an account when this is needed for support, operation or preventing abuse (for example when you ask us for help). Every such access is logged with time and type; we delete this log after 12 months. For the same purpose the server keeps an operations log without IP addresses and without content: sign-ins (type of sign-in), AI requests (only feature, model, result and credits – never your messages or the answer), price alert checks and e-mails sent (only their type). Partner searches and partner clicks are logged without any link to an account (only the kind of search or the partner, for flights the airport codes). The operations log is deleted after 30 days and together with your account. Legal basis: Art. 6(1)(f) GDPR (secure operation, helping with problems). In addition we count searches and partner clicks as plain daily totals, to see what people look for and what works: the kind of search, for flights the airport codes, for hotel and train searches only the country (never the place or the coordinates), for activities only a city from our fixed place list, whether there were results, and for clicks the partner and the spot in the app. These totals contain no IP address, no account and no search text and cannot be linked to a person; we therefore keep them without a time limit. Legal basis: Art. 6(1)(f) GDPR (improving the service).

Sign-in with Google or Apple

Instead of an e-mail code you can sign in with your Google or Apple account. After you agree, the provider passes us a signed sign-in token. From it we store only your user ID at that provider, your e-mail address (with Apple possibly an anonymous relay address from Apple) and, if provided, your name as display name. We receive no password and no access to other data in your Google or Apple account, and we store no access tokens. On the web, the providers' sign-in scripts are loaded only when you open the sign-in screen; your IP address is transmitted to the provider in the process.

Login e-mails

We send the login code by e-mail via Brevo (Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France). Your e-mail address and the content of the e-mail (the code) are transmitted; Brevo processes the data in the EU. We have a data processing agreement with Brevo under Art. 28 GDPR. Brevo keeps sending logs (recipient, time, delivery status) according to its own retention periods. Legal basis: Art. 6 (1) (b) GDPR.

Sharing trips

You can share a trip with friends via a link or code. The link is valid for 14 days. Anyone joining needs their own account.

Legal basis: Art. 6 (1) (b) GDPR.

Planning together: activity log, who is here, receipt photos, shared tickets

Activity log. For shared trips we keep a log of who changed what (e.g. "Added stop: Alfama"), with the time and a title cut to 60 characters – never comment texts or notes. At most the latest 300 entries per trip are kept; they are deleted with the trip and with the account of the person who made the change, and are included in the data export.

Who is here right now. So that fellow travellers can see who is looking at the trip right now, the app sends a short signal about every 20 seconds while a shared trip is open (trip and section, e.g. "Expenses"). It is held only in the server's memory, discarded after 45 seconds and never stored.

Receipt photos. If you add a receipt photo to an expense on a trip you share with others, we store the photo (downsized, at most 1.5 MB) with the trip, your account as uploader and the time on our server in the EU. Only the members of that trip can see it. It is deleted when you delete the expense, when the trip is deleted or when you delete your account. Receipt photos of trips you do not share stay on your device only.

Shared tickets. Tickets (e.g. a boarding pass, a booking confirmation as a PDF, a photo of a museum ticket) stay on your device only by default. Only if you explicitly choose "Share with fellow travellers" on a shared trip do we upload that one ticket (PDF or image, at most 8 MB) and store it with its file name, the plan item it belongs to, the trip, your account as uploader and the time on our server in the EU. Because tickets contain names and booking codes, we store them encrypted (AES-256). Only the members of that trip can see them. A ticket is deleted when you (or the trip's owner) stop sharing it, when the trip is deleted or when you delete your account.

Flight price alerts

When you tap "Watch price" for a flight, we store in your account: the origin and destination airports (or the destination country), the travel dates (a day, a month or a range; return day or trip length, or one way), the number of travellers, your optional highest price, the currency, the ways you want to be told (push, e-mail), the language of the message, when you created the alert, when we last checked it and last notified you, and the price history (the cheapest price found per check, the last 60 checks).

About every 6 hours our server asks the data interface of Travelpayouts/Aviasales (Go Travel Un Limited, Hong Kong, see section 9) for cached flight prices for this route and these dates. Only airport or country codes, dates and the currency are sent – nothing about you; the same routes of several users are looked up together. When the price falls below your highest price or (without one) to a new low, we tell you at most once a day per alert and not during your quiet hours:

Deleting your account

You can delete your account in two ways:

We delete: the account (e-mail address, display name), all sessions and open sign-in codes, travel profile and passport in the account, your AI credit counter, your price alerts, the copy of your trips, your memberships in other people's trips and the invite links you created. Trips you own and have shared with others are not deleted for your fellow travellers but go to the next member (first someone who can edit, among them the one who joined first); their content then stays with these people. Trips only you had are deleted. The data on your device stays until you delete it there – when deleting in the app you can tick a box to delete all trips on the device as well. Data disappears from server backups after 7 days at the latest. (Backups run every night, each backup is deleted after 7 days.)

7. AI features (Anthropic)

For chat, trip plans and suggestions YesTrip uses the AI model Claude by Anthropic. The contracting party for customers in the EU is Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland; its parent company is Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA.

Only when you use an AI feature do we send the following to Anthropic via our server:

Our server only forwards the request and stores no content of it. Your e-mail address and name are not transmitted. Anthropic sees our server's IP address, not yours.

AI credits

The AI costs us money for every request. To keep it available for everyone, each account has a monthly allowance of AI credits (currently 40 per calendar month; e.g. a trip plan costs 5 or 8 credits, a chat message 1 credit). Everything without AI is not limited. For this we process:

If there are very many requests on one day, the app may use a cheaper AI model of the same provider for the rest of the day or pause the AI until midnight; no additional data is processed for this. Legal basis: Art. 6 (1) (b) GDPR (providing the AI features in the agreed scope) and Art. 6 (1) (f) GDPR (protection against abuse and disproportionate costs).

Your travel profile contains only preferences you stated yourself. The app automatically filters out special categories of personal data (Art. 9 GDPR), such as health, religion or political views, as well as ID data and addresses. Please do not write such information in the chat either.

AI answers and AI-generated plans are labelled as AI content in the app (Art. 50 EU AI Act). AI can make mistakes. Check important information such as opening times, entry rules and visas yourself.

8. Maps, place search, routes, place photos, weather, holidays and exchange rates

To make maps, search, photos, weather, holidays and exchange rates work, your device loads data directly from the following services. We do not see these requests ourselves. They receive your IP address, technical information about your browser or device, and the requested place or map area (coordinates, search term).

ServiceUsed forProvider
OpenFreeMapmap tilesHyperknot Software Kft., Hungary, openfreemap.org – according to its privacy policy no IP addresses are stored in normal operation, logs are kept 7 days; according to its own statement it may use Cloudflare, Inc., USA, as a content delivery network
Photonplace searchkomoot GmbH, Potsdam, Germany, photon.komoot.io
routing.openstreetmap.de (OSRM)walking and driving routesFOSSGIS e.V., Germany, routing.openstreetmap.de
Wikipedia / Wikimedia Commons / Wikidataphotos of places and hotels (Wikidata only to find the matching image – only place names or IDs are sent)Wikimedia Foundation, Inc., San Francisco, USA
Open-Meteoweather for each trip day (forecast; for trips further ahead the typical weather of past years) – only coordinates and dates are sentOpenMeteo GmbH, Hintere Schilligmatte 6, 6463 Bürglen, Switzerland, open-meteo.com – Switzerland has an adequacy decision of the European Commission (Art. 45 GDPR)
Overpass API"Discover nearby" (restaurants, museums, viewpoints around a place) – coordinates and the chosen category are sentmain server: FOSSGIS e.V., Germany, overpass-api.de; only if it does not answer, fallback: Private.coffee – Verein zur Förderung von Privatsphäre und digitaler Souveränität, Graz, Austria, private.coffee
Frankfurterexchange rates for shared costs and "Good to know" (European Central Bank reference rates) – only the currency code is sentopen-source project Frankfurter, frankfurter.dev; delivered through Cloudflare, Inc., USA (certified under the EU-U.S. Data Privacy Framework, Art. 45 GDPR). According to the operator, no IP addresses and no requests are logged.
Airline logos (pics.avs.io)airline logos in flight results – only the airline code is sentlogo service of Travelpayouts (Go Travel Un Limited, Hong Kong), travelpayouts.com
Nager.Datepublic holidays in the destination country ("What’s on") – only country and year are sentTino Hager, Austria, date.nager.at

Location: on the map you can show your current location ("where am I"). Your browser or Android asks for permission first. The location is used only on your device to move the map there. We do not receive it. The map service only sees which map area your device loads.

The app also contains built-in data from Natural Earth and OurAirports (countries, airports). No requests to third parties are made for this.

YesTrip shows flights, accommodation and tours from partners (e.g. Travelpayouts/Aviasales, Booking.com, GetYourGuide, Viator; possibly later Klook, Tiqets, Expedia, Stay22, Skyscanner).

Search: when you search in the app, our server queries the partners' interfaces with place, travel dates and, where relevant, number of guests. No personal data about you is transmitted. Results are cached on our server for up to 30 minutes without any link to you.

Clicking a partner link: the link opens the partner's website or app. From there, the partner's privacy policy applies. The partner learns that you came from YesTrip so it can attribute a commission to us. For this the partner may use cookies or similar technologies on its own site. We do not pass any of your data (name, e-mail, payment data) to partners. We only receive commission reports from partners (e.g. date, type and status of a booking, booking value, commission and a short description of the booking) – without names, e-mail addresses or payment data of travellers.

Further partner categories (through the partner network Travelpayouts): flights (Kiwi.com), rental cars (e.g. Localrent, GetRentaCar, EconomyBookings, QEEQ, Auto Europe), airport transfers (e.g. Welcome Pickups, Kiwitaxi, GetTransfer, Intui.travel), tours, tickets and city passes (e.g. Klook, Tiqets, KKday, WeGoTrip, Go City), travel eSIMs (e.g. Airalo, Saily, Yesim, GigSky, Drimsim), travel insurance (EKTA), compensation for delayed flights (AirHelp, Compensair), bike and scooter rental (BikesBooking) and luggage storage (Radical Storage). The app only shows these hints where they fit your trip (e.g. eSIM only for trips outside EU roaming) and always labels them "Ad".

How these partner links work: the app loads no scripts from partners or networks. When you tap such a link, it first opens our own server (app.yestrip.app/api/go). It turns the public address of the partner page (e.g. the page for rental cars in Georgia) into a partner link through the Travelpayouts interface and redirects you. We only send Travelpayouts this partner address, our partner ID and a coarse note of where in the app the link was (e.g. "Book") – no data about you. Created links are stored for up to 30 days without any link to you. Your IP address is only used briefly in memory to limit abusive numbers of requests; it is not stored. After the redirect your browser contacts the servers of Travelpayouts; Travelpayouts then sets the attribution (tracking) for the partner so it can attribute a commission to us. From there, the privacy policies of Travelpayouts and of the partner apply. Travelpayouts is operated by Go Travel Un Limited, 4007 Central Plaza, 18 Harbour Road, Wanchai, Hong Kong (according to Travelpayouts' privacy policy of 14 August 2026). Hong Kong is a third country without an EU adequacy decision; the transfer only happens through your own click on the link.

Legal basis for showing partner offers: Art. 6 (1) (f) GDPR (legitimate interest in financing the free service).

10. No cookies, no third-party trackers – our own audience measurement and anonymous usage numbers

We use no cookies, no third-party analytics tools and no advertising ID on our pages or in the app. That is why there is no cookie banner. What YesTrip stores on your device (see section 4) is strictly necessary for the app to work (§ 25 (2) no. 2 TDDDG).

On yestrip.app we use a small script of our own to measure how our website is used. It runs only on our own server, with no service provider and no transfer to third parties. We record: the page viewed, the referring website (domain only), campaign parameters in the address (utm_*), visible time and scroll depth per page, clicks on our buttons and on links to other websites (target domain only), device type, browser and operating system (derived from the user agent), browser language, screen width (in four bands), time zone and country.

We set no cookies and store nothing on your device for this measurement. The only exceptions on the website: if you close the hint “This page is also available in German/English”, your browser remembers that in local storage (entry “yt-lh”, not linked to you) so the hint does not come back. If you pick a language with the language switch, your browser remembers that choice (entry “yt-lang”, only “de” or “en”) so the start page does not redirect you again. Otherwise, if your browser is set to German, the English start page forwards you to the German one; only your browser’s language setting is read for this, nothing is sent. Both are required for the function you asked for (§ 25(2) no. 2 TDDDG). To group the page views of one day into a visit, we compute a shortened, irreversible checksum (hash) from your IP address, your user agent and a random daily key. The daily key is deleted and replaced every day at midnight (UTC), so you cannot be recognised across days, and we cannot recover the IP address from the hash either. Your IP address is not stored. It is only used briefly in memory to compute the hash and to determine the country (via a local table, without asking any third party).

If "Global Privacy Control" or "Do Not Track" is switched on in your browser, the script sends nothing and our server discards such requests. Without JavaScript we only count the page view (day, page, device type).

After you have created your first own trip, the app asks you once: "Help us improve YesTrip – send anonymous usage numbers?" Nothing is sent unless you tap "Yes, sure". You can change this at any time under Settings → "Anonymous usage numbers".

What is sent if you agree – only to our own server, no third-party analytics service:

What is never sent: cities and places of your trips (except well-known sights from our fixed list, see above), addresses, coordinates or location, trip names, trip dates, flight routes, texts, notes, chat, names, e-mail address, account ID, advertising ID or device identifiers. The data is never combined into one person's travel history.

Your device's IP address is transmitted with every request for technical reasons. We do not store it with the usage numbers; it is only held briefly in memory to block too many requests (see section 5).

Before you have answered, the app records no events at all. Only after you agree, the app collects at most 50 events on your device and sends them in batches; nothing is sent while offline.

11. Feedback in the app

In the settings you can send us a message under "Give feedback": report a bug, suggest an idea, ask a question or give general feedback.

12. Android app

The Android app uses the following permissions:

Rating dialog (Google Play In-App Review): at certain moments (e.g. after you played or shared a trip recap, or created your third trip – never in the first 3 days, at most once every 120 days and three times in total) the app asks Google Play to show its rating dialog. The dialog is shown and processed by Google under Google's privacy policy; whether it appears is decided by Google. We do not learn whether or how you rated. The app only stores on your device when it last asked.

In addition, through the built-in components for notifications: show notifications (for push notifications and reminders; from Android 13 you are asked first), restore reminders after the device restarts, schedule reminders and briefly keep the device awake for them. These permissions give us no access to data on your device.

The app is distributed via Google Play. Google's privacy policy applies to download and updates. The app contains no crash reporting or usage statistics tool (neither from Google nor from other providers). Once the app is available on Google Play, Google may provide us with aggregated statistics in the Play Console (e.g. installs, crashes) that we cannot link to a person.

Push notifications (only if you turn them on)

To tell you about changes to shared trips (new expenses, polls, comments, tasks assigned to you, people joining, changed trip dates) we use Firebase Cloud Messaging (FCM) by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as our processor. Firebase gives your device a random device identifier (token). We store it with your account, the platform, when it was registered and when a notification was last delivered. For each notification we send Google only this token, the trip name, a short text (e.g. "3 new expenses in Lisbon") and the internal trip id so that a tap opens the trip – no other trip content and no e-mail address. Data may be transferred to the USA; Google is certified under the EU-US Data Privacy Framework, and standard contractual clauses also apply.

13. Children

YesTrip is not directed at children under 16. Only people aged 16 or over may create an account.

14. Your rights

You have the right to:

Write to us at contact@yestrip.app. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), e.g. the authority where you live or the authority responsible for us: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz (State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate), Hintere Bleiche 34, 55116 Mainz, Germany, www.datenschutz.rlp.de.

15. No obligation to provide data, no automated decisions

You are not obliged to give us any data. To use YesTrip, however, we need your e-mail address for the account; without it you cannot use the app. There is no automated decision-making under Art. 22 GDPR. The AI only makes suggestions.

16. Changes

We update this policy when YesTrip or the law changes. The version published here applies.

Back to home