Privacy policy
Stand: October 2026
The German version of this privacy policy is the binding one. This English version is provided for convenience.
In short
- YesTrip needs an account (just your e-mail address, no password). Your trips, travel profile and travel passport are stored in your account on our server in the EU and synced with your devices automatically. Tickets, photos, cover images and the chat stay on your device only – unless you explicitly share a ticket or receipt photo with the members of a shared trip (section 6). You can delete your account at any time.
- No cookies, no third-party analytics tools, no advertising ID. On our website we measure its use with a script of our own, without cookies and without storing your IP address; accounts and their contents are evaluated in summarised form only, never per person (sections 6 and 10). Only if you explicitly agree does the app send anonymous usage numbers to our own server (section 10) – never destinations, names or texts.
- If you use the AI, your message together with your trips and travel profile goes through our server to Anthropic (USA). Our server stores no content of it – only how many AI credits you used in the month (section 7).
- Maps, place search, routes and place photos are loaded from open services. They see your IP address and the place you are looking at.
- We earn money with partner links. Once you click one, the partner's privacy rules apply.
1. Controller
John Henry Herzel – YesTrip
c/o flexdienst – #20713, Kurt-Schumacher-Straße 74
67663 Kaiserslautern
Germany
E-mail: contact@yestrip.app
This policy applies to the website yestrip.app ("landing page"), the web app at app.yestrip.app and the Android app "YesTrip" (together "YesTrip").
2. Data protection officer
We are not legally required to appoint a data protection officer (fewer than 20 people regularly process personal data, § 38 BDSG). For data protection questions, write to the e-mail address above.
3. Overview: where your data is
| Data | Where |
|---|---|
| Trips (places, dates, plan items, notes) | device and your account on our server |
| Travel profile (preferences you stated) | device and your account on our server |
| Travel passport (visited countries, cities, flights) | device and your account on our server |
| E-mail address, display name | our server |
| AI credits used per month (one number) | our server |
| Flight price alerts (route, dates, highest price, price history) | our server |
| AI chat | your device only (sent to Anthropic when you use the AI, see section 7) – never in your account |
| Tickets, photos, cover images | your device only (tickets and receipt photos you explicitly share: also on our server, only for the trip's members) |
| Settings (language, photos on/off etc.) | your device only |
If our server cannot be reached (e.g. offline on a plane), the app keeps working with the data on your device and syncs as soon as there is a connection again.
The "travel passport" in YesTrip is a collection of the places you visited and flights you took. It contains no identity document data.
4. Storage on your device
YesTrip stores your content in the local storage of your browser or the app (localStorage and IndexedDB), so the app is fast and also works offline. We have no access to this device storage; what is additionally kept in your account is described in section 6. You can delete it at any time by deleting the content in the app, clearing the site data in your browser or uninstalling the app.
Access to device storage is strictly necessary for the function you requested and is therefore allowed without consent (§ 25 (2) no. 2 TDDDG). The legal basis for the processing is Art. 6 (1) (b) GDPR (providing the app you want to use).
5. Providing the website and app, server logs
When you open the landing page or the web app, or when the app contacts our server (AI, partner search, account), our server processes technically necessary data: IP address, date and time, requested address, amount of data transferred, browser or app identifier (user agent) and status code.
- Purpose: delivering pages and features, protection against abuse and attacks (e.g. limiting too many requests from one IP address).
- Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is secure and stable operation.
- Retention: we do not write access logs with IP addresses. The IP address is only processed in memory to deliver a request and to limit too many requests; these counters expire after one hour at the latest. Server error messages contain neither IP addresses nor e-mail addresses.
Hosting: our server is run by Hostinger International Ltd., 61 Lordou Vironos str., 6023 Larnaca, Cyprus, data centre in Düsseldorf, Germany. We have a data processing agreement with Hostinger under Art. 28 GDPR (Hostinger's Data Processing Addendum, part of its terms).
Backups: the database with the accounts is backed up every night. The backups are kept only on our own server at Hostinger (see above); we do not use any other backup provider. We keep each backup for 7 days, after which it is deleted automatically. Legal basis: Art. 6 (1) (f) GDPR (protection against data loss).
The landing page loads no content from third parties. Fonts are served from our own server.
Contact by e-mail
If you write to contact@yestrip.app, we process your e-mail address, your name (if given) and the content of your message to reply to you. The mailbox is hosted by Hostinger (see above, data processing agreement under Art. 28 GDPR). Legal basis: Art. 6 (1) (b) GDPR if it concerns your account or the use of YesTrip, otherwise Art. 6 (1) (f) GDPR (answering your request). We delete the e-mails once the request has been dealt with, at the latest after 12 months, unless statutory retention obligations require otherwise.
6. Account
You need an account to use YesTrip. You sign in with your e-mail address and a code we send you. With the account your trips are available on all your devices, you can share them with friends, and we can limit AI usage fairly (section 7).
While you are signed in, the app syncs your trips, travel profile and travel passport with your account automatically. On your first sign-in, trips that were only on your device are moved into your account. Our server is located in the EU (see section 5).
What we store:
- e-mail address and display name
- login codes: only as a check value (hash), valid for 10 minutes, at most 5 attempts
- session: only as a check value (hash), valid for 90 days, plus a short device label so you can recognise your sessions
- your trips, your travel profile and your travel passport
- the number of AI credits you used in each month (section 7)
- for shared trips: who is a member and with which role (view or edit)
- invite links: only as a check value (hash), valid for 14 days
What we do not store: tickets, photos, cover images and your AI chat (exception: tickets and receipt photos you explicitly share with a shared trip, see "Planning together"). These stay on your device (for chat messages sent when you use the AI, see section 7). There are no passwords – you sign in with a code sent by e-mail.
Please do not enter data in trips and notes that does not belong there (e.g. ID or credit card numbers). Trips are stored in your account on our server.
- Purpose: account, syncing between your devices, sharing trips, counting AI credits.
- Legal basis: Art. 6 (1) (b) GDPR (contract for using YesTrip).
- Retention: until you delete the account. Expired codes, sessions and invites become invalid and are deleted every hour. If you have not signed in for 24 months, we delete your account automatically; we remind you by e-mail 30 days before, so you can keep it by signing in.
Statistics on accounts and their contents
When you sign in, we derive the country from your IP address once and store only the country code (e.g. "DE") with your account – we do not store the IP address itself. We also store the day you last used YesTrip and when a trip was first saved.
For our product statistics we evaluate the contents of accounts – trips (destination, dates, trip style, group size, expenses), travel profile, passport and wish list – in summarised form only, for example "average cost per day in Portugal" or "most common destinations of accounts from Austria". We see no information about individual people, no e-mail addresses, names or free text; profile entries appear only when at least three accounts gave the same entry.
- Purpose: improving and developing YesTrip (e.g. which destinations are in demand, what trips there cost).
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
- Objection (Art. 21 GDPR): at any time by e-mail to contact@yestrip.app. Your account is then left out of all evaluations.
Operation, support and abuse prevention
As the operator we can view the data of an account when this is needed for support, operation or preventing abuse (for example when you ask us for help). Every such access is logged with time and type; we delete this log after 12 months. For the same purpose the server keeps an operations log without IP addresses and without content: sign-ins (type of sign-in), AI requests (only feature, model, result and credits – never your messages or the answer), price alert checks and e-mails sent (only their type). Partner searches and partner clicks are logged without any link to an account (only the kind of search or the partner, for flights the airport codes). The operations log is deleted after 30 days and together with your account. Legal basis: Art. 6(1)(f) GDPR (secure operation, helping with problems). In addition we count searches and partner clicks as plain daily totals, to see what people look for and what works: the kind of search, for flights the airport codes, for hotel and train searches only the country (never the place or the coordinates), for activities only a city from our fixed place list, whether there were results, and for clicks the partner and the spot in the app. These totals contain no IP address, no account and no search text and cannot be linked to a person; we therefore keep them without a time limit. Legal basis: Art. 6(1)(f) GDPR (improving the service).
Sign-in with Google or Apple
Instead of an e-mail code you can sign in with your Google or Apple account. After you agree, the provider passes us a signed sign-in token. From it we store only your user ID at that provider, your e-mail address (with Apple possibly an anonymous relay address from Apple) and, if provided, your name as display name. We receive no password and no access to other data in your Google or Apple account, and we store no access tokens. On the web, the providers' sign-in scripts are loaded only when you open the sign-in screen; your IP address is transmitted to the provider in the process.
- Purpose and legal basis: signing in to your YesTrip account (Art. 6(1)(b) GDPR).
- Disconnect: in the app under Settings → Connected sign-ins; it is deleted together with your account.
- Processing by the providers is governed by their own privacy policies: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (policies.google.com/privacy); Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland (apple.com/legal/privacy).
Login e-mails
We send the login code by e-mail via Brevo (Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France). Your e-mail address and the content of the e-mail (the code) are transmitted; Brevo processes the data in the EU. We have a data processing agreement with Brevo under Art. 28 GDPR. Brevo keeps sending logs (recipient, time, delivery status) according to its own retention periods. Legal basis: Art. 6 (1) (b) GDPR.
Sharing trips
You can share a trip with friends via a link or code. The link is valid for 14 days. Anyone joining needs their own account.
- Members of a trip see the trip and the display names of the other members.
- The owner of the trip additionally sees the members' e-mail addresses.
- Members with edit rights can change the trip.
- Anyone with a valid link can join. Only share it with people who should see the trip.
Legal basis: Art. 6 (1) (b) GDPR.
Planning together: activity log, who is here, receipt photos, shared tickets
Activity log. For shared trips we keep a log of who changed what (e.g. "Added stop: Alfama"), with the time and a title cut to 60 characters – never comment texts or notes. At most the latest 300 entries per trip are kept; they are deleted with the trip and with the account of the person who made the change, and are included in the data export.
Who is here right now. So that fellow travellers can see who is looking at the trip right now, the app sends a short signal about every 20 seconds while a shared trip is open (trip and section, e.g. "Expenses"). It is held only in the server's memory, discarded after 45 seconds and never stored.
Receipt photos. If you add a receipt photo to an expense on a trip you share with others, we store the photo (downsized, at most 1.5 MB) with the trip, your account as uploader and the time on our server in the EU. Only the members of that trip can see it. It is deleted when you delete the expense, when the trip is deleted or when you delete your account. Receipt photos of trips you do not share stay on your device only.
Shared tickets. Tickets (e.g. a boarding pass, a booking confirmation as a PDF, a photo of a museum ticket) stay on your device only by default. Only if you explicitly choose "Share with fellow travellers" on a shared trip do we upload that one ticket (PDF or image, at most 8 MB) and store it with its file name, the plan item it belongs to, the trip, your account as uploader and the time on our server in the EU. Because tickets contain names and booking codes, we store them encrypted (AES-256). Only the members of that trip can see them. A ticket is deleted when you (or the trip's owner) stop sharing it, when the trip is deleted or when you delete your account.
- Purpose and legal basis: planning a trip together that you shared or joined (Art. 6(1)(b) GDPR).
Flight price alerts
When you tap "Watch price" for a flight, we store in your account: the origin and destination airports (or the destination country), the travel dates (a day, a month or a range; return day or trip length, or one way), the number of travellers, your optional highest price, the currency, the ways you want to be told (push, e-mail), the language of the message, when you created the alert, when we last checked it and last notified you, and the price history (the cheapest price found per check, the last 60 checks).
About every 6 hours our server asks the data interface of Travelpayouts/Aviasales (Go Travel Un Limited, Hong Kong, see section 9) for cached flight prices for this route and these dates. Only airport or country codes, dates and the currency are sent – nothing about you; the same routes of several users are looked up together. When the price falls below your highest price or (without one) to a new low, we tell you at most once a day per alert and not during your quiet hours:
- by push via Firebase Cloud Messaging (see section 12 "Push notifications"; Google receives the device token, the route, the price and the internal alert id so a tap opens the search),
- by e-mail via Brevo (see "Login e-mails"), only if you turn it on for that alert; your e-mail address and the content of the e-mail are transmitted (route, dates, new and previous price, a link into the app – no link to a partner).
- Purpose and legal basis: the price alert you asked for (Art. 6(1)(b) GDPR); push notifications only with your consent (Art. 6(1)(a) GDPR).
- Storage period: until you delete the alert. Once the last departure day has passed, the alert ends and is deleted automatically 30 days later. Deleting your account deletes all alerts immediately. The alerts and their price history are part of the data export.
Deleting your account
You can delete your account in two ways:
- in the app: Settings → Account & sharing → "Delete account", confirmed by typing "DELETE". The deletion on our server happens immediately.
- without the app: by e-mail to contact@yestrip.app, please from your account's e-mail address. We then delete within 30 days at the latest and confirm it to you. Instructions are on the page Delete your account.
We delete: the account (e-mail address, display name), all sessions and open sign-in codes, travel profile and passport in the account, your AI credit counter, your price alerts, the copy of your trips, your memberships in other people's trips and the invite links you created. Trips you own and have shared with others are not deleted for your fellow travellers but go to the next member (first someone who can edit, among them the one who joined first); their content then stays with these people. Trips only you had are deleted. The data on your device stays until you delete it there – when deleting in the app you can tick a box to delete all trips on the device as well. Data disappears from server backups after 7 days at the latest. (Backups run every night, each backup is deleted after 7 days.)
7. AI features (Anthropic)
For chat, trip plans and suggestions YesTrip uses the AI model Claude by Anthropic. The contracting party for customers in the EU is Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland; its parent company is Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA.
Only when you use an AI feature do we send the following to Anthropic via our server:
- your message or request and the latest messages of the chat (up to 10), so the AI knows the context
- the list of your trips (place and dates) and, for AI features for a specific trip, its plan items
- your travel profile
- if you let the travel profile learn preferences from the chat: your latest own chat messages (up to 30)
Our server only forwards the request and stores no content of it. Your e-mail address and name are not transmitted. Anthropic sees our server's IP address, not yours.
AI credits
The AI costs us money for every request. To keep it available for everyone, each account has a monthly allowance of AI credits (currently 40 per calendar month; e.g. a trip plan costs 5 or 8 credits, a chat message 1 credit). Everything without AI is not limited. For this we process:
- in your account: the number of credits used per month (no content, no times of single requests). It is deleted with the account;
- without reference to a person: per day the number of AI requests, the estimated cost and how often requests were declined (e.g. because the allowance was used up);
- to prevent abuse we briefly count in memory how many requests come from your account and from an IP address (at most one hour). The IP address is not stored.
If there are very many requests on one day, the app may use a cheaper AI model of the same provider for the rest of the day or pause the AI until midnight; no additional data is processed for this. Legal basis: Art. 6 (1) (b) GDPR (providing the AI features in the agreed scope) and Art. 6 (1) (f) GDPR (protection against abuse and disproportionate costs).
- Purpose: answering your request.
- Legal basis: Art. 6 (1) (b) GDPR (the AI feature you use).
- Transfer to a third country: Anthropic processes the data in the USA. The basis is the European Commission's standard contractual clauses (Art. 46 (2) (c) GDPR), which are part of Anthropic's Data Processing Addendum. Anthropic is not certified under the EU-US Data Privacy Framework.
- Training: under Anthropic's commercial terms, content sent via the API is not used to train AI models ("Anthropic may not train models on Customer Content from Services").
- Retention at Anthropic: according to Anthropic, inputs and outputs are kept only for a limited time – they are deleted automatically within 30 days –, and longer only where needed to detect misuse or required by law.
- Data processing: Anthropic's Data Processing Addendum is incorporated by reference into Anthropic's commercial terms; under it Anthropic processes the data as a processor (Art. 28 GDPR).
Your travel profile contains only preferences you stated yourself. The app automatically filters out special categories of personal data (Art. 9 GDPR), such as health, religion or political views, as well as ID data and addresses. Please do not write such information in the chat either.
AI answers and AI-generated plans are labelled as AI content in the app (Art. 50 EU AI Act). AI can make mistakes. Check important information such as opening times, entry rules and visas yourself.
8. Maps, place search, routes, place photos, weather, holidays and exchange rates
To make maps, search, photos, weather, holidays and exchange rates work, your device loads data directly from the following services. We do not see these requests ourselves. They receive your IP address, technical information about your browser or device, and the requested place or map area (coordinates, search term).
| Service | Used for | Provider |
|---|---|---|
| OpenFreeMap | map tiles | Hyperknot Software Kft., Hungary, openfreemap.org – according to its privacy policy no IP addresses are stored in normal operation, logs are kept 7 days; according to its own statement it may use Cloudflare, Inc., USA, as a content delivery network |
| Photon | place search | komoot GmbH, Potsdam, Germany, photon.komoot.io |
| routing.openstreetmap.de (OSRM) | walking and driving routes | FOSSGIS e.V., Germany, routing.openstreetmap.de |
| Wikipedia / Wikimedia Commons / Wikidata | photos of places and hotels (Wikidata only to find the matching image – only place names or IDs are sent) | Wikimedia Foundation, Inc., San Francisco, USA |
| Open-Meteo | weather for each trip day (forecast; for trips further ahead the typical weather of past years) – only coordinates and dates are sent | OpenMeteo GmbH, Hintere Schilligmatte 6, 6463 Bürglen, Switzerland, open-meteo.com – Switzerland has an adequacy decision of the European Commission (Art. 45 GDPR) |
| Overpass API | "Discover nearby" (restaurants, museums, viewpoints around a place) – coordinates and the chosen category are sent | main server: FOSSGIS e.V., Germany, overpass-api.de; only if it does not answer, fallback: Private.coffee – Verein zur Förderung von Privatsphäre und digitaler Souveränität, Graz, Austria, private.coffee |
| Frankfurter | exchange rates for shared costs and "Good to know" (European Central Bank reference rates) – only the currency code is sent | open-source project Frankfurter, frankfurter.dev; delivered through Cloudflare, Inc., USA (certified under the EU-U.S. Data Privacy Framework, Art. 45 GDPR). According to the operator, no IP addresses and no requests are logged. |
| Airline logos (pics.avs.io) | airline logos in flight results – only the airline code is sent | logo service of Travelpayouts (Go Travel Un Limited, Hong Kong), travelpayouts.com |
| Nager.Date | public holidays in the destination country ("What’s on") – only country and year are sent | Tino Hager, Austria, date.nager.at |
- Purpose: showing maps, searching places, calculating routes, photos of places, weather, places nearby, holidays and exchange rates.
- Legal basis: Art. 6 (1) (b) GDPR where you use these features, and Art. 6 (1) (f) GDPR (legitimate interest in a working map without running our own map servers).
- You can switch off place photos from Wikipedia/Wikimedia in the settings. These requests are then no longer made.
- Wikimedia Foundation, Inc., 1 Sansome Street, Suite 1895, San Francisco, CA 94104, USA. Your device loads the image files directly from Wikimedia (upload.wikimedia.org); Wikimedia receives your IP address in the process. Our server remembers which photo belongs to a place, without any link to you, so that not every device has to search Wikipedia again. The Wikimedia Foundation is not certified under the EU-US Data Privacy Framework. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in showing photos of places). Place photos are switched on by default; you can switch them off at any time in the settings under "Place photos".
- Results are cached on your device so the same request is not made again and again: routes, weather (forecast 3 hours, typical weather 30 days), places nearby, exchange rates (12 hours) and holidays (30 days).
Location: on the map you can show your current location ("where am I"). Your browser or Android asks for permission first. The location is used only on your device to move the map there. We do not receive it. The map service only sees which map area your device loads.
The app also contains built-in data from Natural Earth and OurAirports (countries, airports). No requests to third parties are made for this.
9. Partner search and partner links
YesTrip shows flights, accommodation and tours from partners (e.g. Travelpayouts/Aviasales, Booking.com, GetYourGuide, Viator; possibly later Klook, Tiqets, Expedia, Stay22, Skyscanner).
Search: when you search in the app, our server queries the partners' interfaces with place, travel dates and, where relevant, number of guests. No personal data about you is transmitted. Results are cached on our server for up to 30 minutes without any link to you.
Clicking a partner link: the link opens the partner's website or app. From there, the partner's privacy policy applies. The partner learns that you came from YesTrip so it can attribute a commission to us. For this the partner may use cookies or similar technologies on its own site. We do not pass any of your data (name, e-mail, payment data) to partners. We only receive commission reports from partners (e.g. date, type and status of a booking, booking value, commission and a short description of the booking) – without names, e-mail addresses or payment data of travellers.
Further partner categories (through the partner network Travelpayouts): flights (Kiwi.com), rental cars (e.g. Localrent, GetRentaCar, EconomyBookings, QEEQ, Auto Europe), airport transfers (e.g. Welcome Pickups, Kiwitaxi, GetTransfer, Intui.travel), tours, tickets and city passes (e.g. Klook, Tiqets, KKday, WeGoTrip, Go City), travel eSIMs (e.g. Airalo, Saily, Yesim, GigSky, Drimsim), travel insurance (EKTA), compensation for delayed flights (AirHelp, Compensair), bike and scooter rental (BikesBooking) and luggage storage (Radical Storage). The app only shows these hints where they fit your trip (e.g. eSIM only for trips outside EU roaming) and always labels them "Ad".
How these partner links work: the app loads no scripts from partners or networks. When you tap such a link, it first opens our own server (app.yestrip.app/api/go). It turns the public address of the partner page (e.g. the page for rental cars in Georgia) into a partner link through the Travelpayouts interface and redirects you. We only send Travelpayouts this partner address, our partner ID and a coarse note of where in the app the link was (e.g. "Book") – no data about you. Created links are stored for up to 30 days without any link to you. Your IP address is only used briefly in memory to limit abusive numbers of requests; it is not stored. After the redirect your browser contacts the servers of Travelpayouts; Travelpayouts then sets the attribution (tracking) for the partner so it can attribute a commission to us. From there, the privacy policies of Travelpayouts and of the partner apply. Travelpayouts is operated by Go Travel Un Limited, 4007 Central Plaza, 18 Harbour Road, Wanchai, Hong Kong (according to Travelpayouts' privacy policy of 14 August 2026). Hong Kong is a third country without an EU adequacy decision; the transfer only happens through your own click on the link.
Legal basis for showing partner offers: Art. 6 (1) (f) GDPR (legitimate interest in financing the free service).
10. No cookies, no third-party trackers – our own audience measurement and anonymous usage numbers
We use no cookies, no third-party analytics tools and no advertising ID on our pages or in the app. That is why there is no cookie banner. What YesTrip stores on your device (see section 4) is strictly necessary for the app to work (§ 25 (2) no. 2 TDDDG).
Audience measurement on our website (cookie-free)
On yestrip.app we use a small script of our own to measure how our website is used. It runs only on our own server, with no service provider and no transfer to third parties. We record: the page viewed, the referring website (domain only), campaign parameters in the address (utm_*), visible time and scroll depth per page, clicks on our buttons and on links to other websites (target domain only), device type, browser and operating system (derived from the user agent), browser language, screen width (in four bands), time zone and country.
We set no cookies and store nothing on your device for this measurement. The only exceptions on the website: if you close the hint “This page is also available in German/English”, your browser remembers that in local storage (entry “yt-lh”, not linked to you) so the hint does not come back. If you pick a language with the language switch, your browser remembers that choice (entry “yt-lang”, only “de” or “en”) so the start page does not redirect you again. Otherwise, if your browser is set to German, the English start page forwards you to the German one; only your browser’s language setting is read for this, nothing is sent. Both are required for the function you asked for (§ 25(2) no. 2 TDDDG). To group the page views of one day into a visit, we compute a shortened, irreversible checksum (hash) from your IP address, your user agent and a random daily key. The daily key is deleted and replaced every day at midnight (UTC), so you cannot be recognised across days, and we cannot recover the IP address from the hash either. Your IP address is not stored. It is only used briefly in memory to compute the hash and to determine the country (via a local table, without asking any third party).
If "Global Privacy Control" or "Do Not Track" is switched on in your browser, the script sends nothing and our server discards such requests. Without JavaScript we only count the page view (day, page, device type).
- Purpose: understanding how our website is found and used, to improve it.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in audience measurement). Nothing is stored on your device; the script is delivered like any web page and runs only in memory. Where information from your browser is used, we consider this permitted without consent under § 25(2) no. 2 TDDDG, because we use the measurement only to operate and improve the service you are using and build no profiles across days or websites.
- Retention: individual visits for 30 days, after that only aggregated daily figures with no link to individual visits; we delete those after 14 months.
- Objection (Art. 21 GDPR): at any time, most easily by switching on "Global Privacy Control" or "Do Not Track" in your browser.
Anonymous usage numbers (only with your consent)
After you have created your first own trip, the app asks you once: "Help us improve YesTrip – send anonymous usage numbers?" Nothing is sent unless you tap "Yes, sure". You can change this at any time under Settings → "Anonymous usage numbers".
What is sent if you agree – only to our own server, no third-party analytics service:
- a random install number created on your device that changes every 90 days. It is not linked to your account, e-mail address or name;
- the name of an event from a fixed list: app opened, onboarding started/finished/skipped, trip created, AI plan used, "Today" view opened, partner link clicked, trip shared (invite created), template shared, offline package ready, recap shared, group expense added, vote started;
- which countries, ratings and well-known sights are popular: the country (as a code, e.g. "PT") of a new trip, a passport entry or a star rating, the number of stars (1–5; for flights only the stars, never the route), and, when you save a well-known sight from our fixed list, its key (e.g. "rome:kolosseum") – for other places only that something was saved. This makes rankings like "most saved places" or "best-rated countries"; they cannot be linked to a person;
- coarse details from fixed lists: trip length as a range (1, 2–3, 4–7, 8–14, 15+ days), trip phase (before/during/after), whether AI was used, where a trip came from (onboarding, form, template, invite, chat), onboarding step, partner name and kind of offer (flight, hotel, activity, eSIM) for a partner click, way of sharing (link, share menu, file; image or video), number of options in a vote, invite role (edit/view);
- app language (German/English), platform (web/Android), app version and the date (day only, no time).
What is never sent: cities and places of your trips (except well-known sights from our fixed list, see above), addresses, coordinates or location, trip names, trip dates, flight routes, texts, notes, chat, names, e-mail address, account ID, advertising ID or device identifiers. The data is never combined into one person's travel history.
Your device's IP address is transmitted with every request for technical reasons. We do not store it with the usage numbers; it is only held briefly in memory to block too many requests (see section 5).
Before you have answered, the app records no events at all. Only after you agree, the app collects at most 50 events on your device and sends them in batches; nothing is sent while offline.
- Purpose: to understand which features are used and where people get stuck, so we can improve the app (e.g. how many finish the onboarding or come back on another day).
- Legal basis: your consent (Art. 6 (1) (a) GDPR; for storing the install number on your device § 25 (1) TDDDG). You can withdraw it at any time with effect for the future by switching it off in Settings. The app then deletes the install number and all events not yet sent from your device.
- Retention: events are deleted automatically after 14 months.
- Recipients: nobody but us. The data is on our server (hosting see section 5).
- As we cannot link the install number to a person, we usually cannot attribute individual entries to you (Art. 11 GDPR). If you tell us your current install number, we delete the matching entries. The app does not display the install number. If you switch off "Anonymous usage numbers" in the settings, the app deletes the number on your device; if you switch it on again, it creates a new one.
11. Feedback in the app
In the settings you can send us a message under "Give feedback": report a bug, suggest an idea, ask a question or give general feedback.
- What is sent: the kind of message (bug, idea, question, general), for general feedback your rating (good, okay, not good), your text (at most 2,000 characters), the name of the screen you write from (e.g. "trip/plan"), optionally your e-mail address if you want a reply by e-mail, and – only if the box "Send technical info" is ticked (on by default) – app version, platform (web, Android or iOS) and app language. Plus a random id of the message so that a retry is not stored twice.
- Screenshot (optional): only if you attach a screenshot yourself, that one image is stored with the message. Make sure it shows nothing you do not want to share.
- Replies: we can answer you and you can write back. Replies are stored together with the message. So that only you can read them, the app creates a secret key that stays on your device; the server only keeps an irreversible hash of it. You find the replies under Settings → My reports. If you gave an e-mail address, we also send the reply there – we use it for nothing else.
- What is not stored: your IP address (it is only held briefly in memory to block too many requests), device or advertising ids, and your account. Feedback is not linked to your account.
- Without an internet connection the feedback stays on your device and is sent the next time the app starts. Alternatively you can send it by e-mail to contact@yestrip.app; then the usual data of an e-mail applies (sender, content).
- If you choose "not good", the app remembers this on your device and does not ask you for a Google Play rating for 60 days (see section 12).
- Purpose: finding bugs, improving the app and – if you want – replying to you.
- Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in improving the app); for the e-mail address you choose to give and the technical info, your consent (Art. 6 (1) (a) GDPR), which you can withdraw at any time.
- Retention: feedback is deleted automatically 12 months after it was sent – with all replies and the screenshot –, earlier on request.
- Recipients: nobody but us. The data is on our server (hosting see section 5).
12. Android app
The Android app uses the following permissions:
- Internet: for maps, search, AI, partner search and account.
- Location (approximate and precise, optional): only if you show your location on the map. You are asked first and can decline.
- Photos and files: only via the Android picker when you choose a photo or file yourself. The app only receives the selected file.
- Sharing: you pass on exports (e.g. PDF) via the Android share menu.
Rating dialog (Google Play In-App Review): at certain moments (e.g. after you played or shared a trip recap, or created your third trip – never in the first 3 days, at most once every 120 days and three times in total) the app asks Google Play to show its rating dialog. The dialog is shown and processed by Google under Google's privacy policy; whether it appears is decided by Google. We do not learn whether or how you rated. The app only stores on your device when it last asked.
In addition, through the built-in components for notifications: show notifications (for push notifications and reminders; from Android 13 you are asked first), restore reminders after the device restarts, schedule reminders and briefly keep the device awake for them. These permissions give us no access to data on your device.
The app is distributed via Google Play. Google's privacy policy applies to download and updates. The app contains no crash reporting or usage statistics tool (neither from Google nor from other providers). Once the app is available on Google Play, Google may provide us with aggregated statistics in the Play Console (e.g. installs, crashes) that we cannot link to a person.
Push notifications (only if you turn them on)
To tell you about changes to shared trips (new expenses, polls, comments, tasks assigned to you, people joining, changed trip dates) we use Firebase Cloud Messaging (FCM) by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as our processor. Firebase gives your device a random device identifier (token). We store it with your account, the platform, when it was registered and when a notification was last delivered. For each notification we send Google only this token, the trip name, a short text (e.g. "3 new expenses in Lisbon") and the internal trip id so that a tap opens the trip – no other trip content and no e-mail address. Data may be transferred to the USA; Google is certified under the EU-US Data Privacy Framework, and standard contractual clauses also apply.
- Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time in the app settings or your phone's system settings.
- Retention: we delete the token when you turn notifications off, sign out (at the latest with the next hourly clean-up), Firebase reports it as invalid, or you delete your account. Which kinds of notifications you get and your quiet hours are stored in your account.
13. Children
YesTrip is not directed at children under 16. Only people aged 16 or over may create an account.
14. Your rights
You have the right to:
- access your stored data (Art. 15 GDPR)
- rectification of incorrect data (Art. 16 GDPR)
- erasure (Art. 17 GDPR) – fastest via "Delete account" in the settings, without the app by e-mail to contact@yestrip.app (see Delete your account)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing based on Art. 6 (1) (f) GDPR (Art. 21 GDPR)
- withdraw consent with effect for the future (Art. 7 (3) GDPR), where we asked for consent
Write to us at contact@yestrip.app. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), e.g. the authority where you live or the authority responsible for us: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz (State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate), Hintere Bleiche 34, 55116 Mainz, Germany, www.datenschutz.rlp.de.
15. No obligation to provide data, no automated decisions
You are not obliged to give us any data. To use YesTrip, however, we need your e-mail address for the account; without it you cannot use the app. There is no automated decision-making under Art. 22 GDPR. The AI only makes suggestions.
16. Changes
We update this policy when YesTrip or the law changes. The version published here applies.