Core Privacy Commitment: TripExpenses does not sell, rent, or monetize your personal data. We do not run third-party advertising SDKs, tracking pixels, or data brokers. Your financial records and travel receipts belong solely to you and your travel group.
1. Information We Collect and How We Use It
TripExpenses is designed with an offline-first architecture. The information processed by the app includes:
- Trip & Expense Information: Expense titles, amounts, foreign currencies, exchange rates, categories, and split ratios that you create. This data is saved locally on your device via SwiftData and synced securely to Cloud Firestore when sharing trips with group members.
- Receipt Scanning & AI Vision:
- Local On-Device Processing: By default, receipt photos scanned using the camera or photo picker are analyzed directly on your device using Apple's Vision framework (OCR). Text extraction runs on your iPhone's Neural Engine.
- Cloud AI Fallback (Google Gemini Flash): For complex, crumpled, or multi-item handwritten receipts, you may choose to invoke Cloud AI. When invoked, receipt images are transmitted ephemerally over encrypted TLS 1.3 to Google Gemini Flash API servers. The image is processed in volatile memory solely to extract line items and amounts, is immediately discarded, is never saved on remote servers, and is never used to train artificial intelligence models. Receipt photos remain stored exclusively on your iPhone's local sandbox storage.
- Location Data (Optional): If you grant location access, TripExpenses records the GPS coordinate (latitude and longitude) of an expense solely to display it on your personal travel map. Location is never tracked continuously in the background and is never shared with third parties.
- Contacts (Optional): If you use the native iOS contact picker to invite friends or autofill payment details, the contact data is accessed purely on-device at the moment of selection. We never upload or scrape your address book.
2. Cloud Synchronization & Multi-User Sharing
When you share a trip via a 6-character code or secret invite link:
- Trip and expense records are encrypted in transit and stored in Google Firebase Cloud Firestore.
- Authentication uses anonymous cryptographic tokens. We do not require or demand your real name, email, or password to join or view a shared trip.
- Only members with your trip’s cryptographic link or explicit host approval can read or modify shared trip expenses.
3. In-App Purchases & Subscriptions
All in-app purchases and subscriptions (TripExpenses Pro) are handled securely through Apple's StoreKit 2 and App Store infrastructure. We do not collect or store your credit card numbers, billing addresses, or banking credentials.
4. Third-Party Services
TripExpenses utilizes minimal, strictly necessary third-party infrastructure:
- Apple Inc.: App Store distribution, StoreKit transaction validation, and Vision OCR framework.
- Google Firebase: Cloud Firestore for real-time group synchronization and Firebase Anonymous Authentication.
- Google Gemini AI: Ephemeral, zero-retention multi-modal API for advanced receipt line-item parsing.
- Exchange Rate APIs: Open-access foreign currency lookup for foreign exchange conversion. No personal user data is attached to exchange rate queries.
5. Data Retention & Deletion
You maintain full control over your data:
- Deleting a trip inside the app permanently deletes all associated local expenses and debt settlements.
- If you are the trip owner, deleting a shared trip purges the trip records and cloud subcollections from Firestore.
- You can reset or wipe all app data at any time by uninstalling the application.
6. Children's Privacy
TripExpenses is not intended for or directed towards children under the age of 13. We do not knowingly collect personal information from children.
7. Contact & Inquiries
If you have any questions or feedback regarding this Privacy Policy or your data, please contact us at:
Entity: JLam Solutions (ABN: 55 450 695 789)
Email: support@jlamsolutions.com.au