Privacy Policy
1. Purpose of Collecting and Using Personal Data
TripPocket collects the minimum personal data necessary to provide the service, and uses it for no purpose other than those listed below.
- To identify your account, keep you signed in, and show you back the courses, trips, and likes you saved
- To produce the travel recommendations, courses, and itineraries you ask for, including AI-generated drafts (see section 8)
- To understand which screens and search terms are actually used, so we can improve recommendation quality and the service
- To find and fix errors, and to block automated abuse and duplicate counting
2. Personal Data We Collect (Web)
- Automatically collected: visit logs, access IP, browser type (Google Analytics)
- Directly collected: your email address when you contact us
- If you sign in with Google: your email address and display name (used to identify your account). An account is created automatically when you first sign in.
- While signed in: your search queries and service activity such as saved courses, likes, ratings and comments
3. Retention and Use Period
Retention differs per item. Records past their period are deleted automatically every day, whether or not they belong to a signed-in user, and deleting your account erases that account’s records immediately regardless of the periods below.
| Item | Retention period |
|---|---|
| Account identifiers (email address, display name) | Until you delete your account — erased immediately on request |
| Saved courses, bookmarks, likes, ratings, comments, and trips you created | Until you delete your account |
| Travel chat conversations and messages (including the text you type) | 30 days |
| Travel chat answer reports (a snapshot of the question and answer at report time) | 180 days |
| Search query logs and search result click logs | 12 months |
| Visit analytics (sessions, page views, in-page actions, error reports) | 12 months |
| Course activity (view, share, and trip-run events) | 12 months |
| Itineraries generated through the AI assistant connector | Up to 24 hours in server memory — never written to the database |
| Server access and error logs | Within 90 days — email addresses and auth tokens are masked at write time |
| Aggregated statistics that cannot identify an individual (e.g. daily view counts) | Kept without a time limit |
4. Use of Cookies
This site may use cookies to improve the service, and you can refuse cookies through your browser settings.
5. Data Collected by the Android App
The TripPocket Android app (package com.itkong.trippocket.android) collects the items below. It uses the same backend as the website, so sections 1–3 apply as written; this section covers what is specific to the app.
- Account information — the Google ID token issued at sign-in is stored encrypted on the device (EncryptedSharedPreferences) and used to authenticate requests. The server reads your email address and display name from that token. The app does not store your email or name on the device.
- App activity — search queries, viewed courses, bookmarked courses, your own trips, and trip-run events (run started, stop arrived, stop skipped, run completed, a random identifier generated per run, and per-leg travel minutes) are sent to the server. They are used to provide the service and improve recommendation quality.
- Access IP address — the app does not send it explicitly, but it reaches the server as part of any HTTP request. It is used only to prevent duplicate counting.
- Location — only when you tap the “my location” button on the map screen does the app read the device’s last known location and show it on the map. That coordinate is neither sent to our server nor stored on the device. The app does not track your location continuously and never requests background location permission.
- Stored on the device only — downloaded trip data (titles, places, addresses, coordinates, times), memos you write, trip-run progress, and your chosen app language. These stay in the app’s private storage and are removed when the app is uninstalled. Android auto-backup is disabled.
- The app collects no advertising identifier and includes no third-party analytics or advertising SDK. It communicates with the Kakao Map SDK to render maps and with external image servers (e.g. the Korea Tourism Organization) to load photos; your sign-in token is not sent with those requests.
6. App Permissions
- Location (optional) — used only to show your current position on the map. If you decline, every screen of the app, including the map, remains usable.
- Internet and network state — used for server communication and to detect whether you are offline.
7. AI Assistant Integration (ChatGPT and other connectors)
TripPocket runs a server (MCP) that AI assistants can connect to. When you connect TripPocket to an assistant such as ChatGPT, the assistant calls the tools below on your behalf. This section describes only what moves along that path.
- What the assistant sends (tool inputs) — travel region, trip length or dates, companion type, budget level, themes of interest, transport mode, the identifier of a course or itinerary you want to open, coordinates or region codes for weather and transport-cost lookups, and the travel request you typed into the assistant. These values are passed by the assistant; TripPocket does not collect them directly.
- What TripPocket returns (tool outputs) — attraction, course, festival, weather, and transport-cost data. All of it comes from the TripPocket database and public data sources; none of it contains your personal data.
- No account linking — along the connector path we never receive your ChatGPT account, name, email address, or any assistant-side identifier. The subject of the access token is the connecting client application, not a person. Connector use is therefore not linked to any TripPocket account, and we cannot tell who asked what.
- Nothing is stored — connector requests create no database records. Only the itinerary the assistant generated is held in server memory for up to 24 hours so it can be reopened by the same identifier, after which it disappears; that value is not linked to any user.
- Operational logs — the request path, response status, processing time, and a token fingerprint used for abuse prevention are recorded. Email addresses and auth tokens are masked automatically at write time, and the access IP is not stored.
- Disconnecting — removing the TripPocket connector in your assistant’s settings ends its access. Access tokens expire after 1 hour and refresh tokens after 30 days.
8. Sharing and Processing by Third Parties
TripPocket does not sell personal data. We use the providers below to operate the service, and each receives only what its purpose requires.
| Recipient | Purpose | What is shared |
|---|---|---|
| Google (Sign-In, Analytics) | Sign-in, visit statistics | Email address and display name (at sign-in), cookie-based visit data |
| OpenAI | Generating travel chat answers and AI course/itinerary drafts | The question you typed and your trip conditions (region, length, companions, budget). No account identifiers are sent. |
| 한국관광공사 TourAPI (Korea Tourism Organization) | Looking up attraction and festival data | Only search conditions such as region and category codes |
| Kakao Mobility · ODsay · TAGO | Car routes, public transport routes, and train fares | Only origin and destination coordinates or region codes |
| Open-Meteo · Frankfurter · Nager.Date | Weather forecasts, exchange rates, public holidays | Only coordinates, dates, and currency codes |
| Cloudflare | Website hosting and delivery | Access IP and request path — the data any HTTP request necessarily carries |
Some of these providers operate servers outside South Korea. Information is passed only to the extent needed to run the service, and each provider follows its own privacy policy. We share data with no other third party except where required by law.
9. Your Rights and How to Exercise Them
- Access and correction — sign in and use My Page to review and edit your saved courses, trips, and activity. For anything else, ask us at the contact address below.
- Deletion — you can erase everything yourself from the account deletion page (section 10). Anonymous records that belong to no account are deleted automatically once their retention period passes.
- Objection and withdrawal of consent — sign out and your activity is no longer linked to an account. You can refuse cookies through your browser settings, and withdraw the app’s location permission at any time in your device settings (section 6).
- Making a request — email the address below and we will act on it and reply within 30 days of receipt. If you disagree with the outcome, reply to the same address.
10. Account and Data Deletion
You can delete your account yourself at any time. On the web, use the account deletion page; in the Android app, go to Settings › Account › Delete account. The web page works without installing the app.
Deletion is permanent and cannot be undone. The account identifiers (email address, display name) and everything linked to the account — saved courses, bookmarks, likes, ratings, comments, trips you created or generated with AI, trip activity and search history — are physically deleted and cannot be restored. Aggregated statistics that cannot identify an individual (such as daily view counts) remain.
Trip data, memos and run history stored on the device are erased when you uninstall the app or clear its storage in Android settings.
11. Contact
Privacy inquiries: [email protected]
For general inquiries, please use the contact page.
Last updated: 2026-08-18