Privacy Policy
Last updated: July 20, 2026
TripSphere ("the app", "we", "us") is a personal travel log developed by Kaylen Stroeken (Belgium). This privacy policy explains what personal data we process, why, and what choices you have. It applies to the mobile app and the website at tripsphere.eu.
1. Controller
The data controller is Kaylen Stroeken. Contact: support@tripsphere.eu. Country: Belgium.
2. What data we collect
We only process data you enter, generate by using optional features, or allow through device permissions:
- Account details: email address and display name, only if you create an account. TripSphere works fully offline without one. An account is only needed for cloud sync, friends and other online features.
- Profile details: optional bio, profile photo and home location (city/country label and coordinates you set, not continuous GPS tracking).
- Travel data: trip names, dates, descriptions, categories, distances and GPX routes you enter or import.
- Photos: photos you manually attach to a trip from your gallery. The app never captures photos automatically.
- Location data: only if you set a home location or import a GPX route. The app never requests background location access.
- Social data: if you use friends, feed, likes or comments: friend links and content you choose to share.
- Push tokens: if you enable notifications, a device push token (via Expo / platform push services) so we can deliver activity alerts.
- Diagnostics: crash and error reports via Sentry (device/app technical data; may include limited context about the failure). Not used for advertising.
3. Why we use data (purposes & legal bases)
- Provide the app (show trips and stats on your device): performance of a contract / your request to use the service.
- Optional cloud sync between devices via Supabase when you are signed in and sync is on: contract / consent to use that feature.
- Optional social features (friends, feed, likes, comments): contract / consent when you turn them on.
- Push notifications for activity you care about: consent (you can disable notifications in system or app settings).
- Stability and security (Sentry crash reports, preventing abuse): legitimate interests, balanced against your rights; you may object where applicable.
- Legal obligations when we must retain or disclose information: legal obligation.
We never use your data for advertising or sell it to third parties for profiling.
4. Storage and security
All travel data is stored locally on your device by default (offline-first).
If you choose cloud sync, data is stored via Supabase
(encrypted in transit via HTTPS/TLS; we configure EU-oriented hosting where available).
We never have access to your password in plain text. Authentication is handled by Supabase Auth with hashed credentials.
5. Sharing with processors / third parties
We do not sell personal data. We use service providers (processors) only as needed:
- Supabase: authentication if you create an account; trip/profile/social storage if you enable cloud sync.
- Sentry: error and crash diagnostics to keep the app reliable.
- Expo / Apple / Google push infrastructure: to deliver notifications if you enable them.
- Legal obligation: if required by law or valid authority request.
Some providers may process data outside the EEA. Where that happens, we rely on appropriate safeguards (such as Standard Contractual Clauses) offered by those providers.
6. Social features and visibility
If you create an account and add friends, they can see content and profile details you make visible.
You can set your profile to private in settings. Trips are visible only to you by default. Home location is never shown to other users.
7. Retention
- Local-only data stays on your device until you delete it or uninstall the app.
- Cloud account and synced data are kept until you delete them or your account.
- After account deletion we remove associated personal data within 30 days, except limited records needed for security or legal duties, and rolling backups that expire automatically.
- Diagnostic events in Sentry follow that provider’s retention settings (typically weeks to a few months).
8. Your rights (GDPR / AVG)
If you are in the EEA/UK (or similar regimes), you can:
- access and receive a copy of your personal data;
- correct inaccurate data;
- delete your account and associated data (in-app or via our delete account page);
- restrict or object to certain processing (including legitimate-interest processing such as diagnostics, where applicable);
- data portability for data you provided, where technically feasible;
- withdraw consent for optional features (sync, social, push) without affecting prior lawful processing;
- lodge a complaint with your supervisory authority (in Belgium: Gegevensbeschermingsautoriteit (GBA)).
Contact support@tripsphere.eu to exercise these rights.
9. Children
The app is not directed at children under 16 (or a higher digital-consent age where required). We do not knowingly collect data from children. If you believe a child created an account, contact us and we will delete it.
10. Website
The marketing website is static and does not set advertising cookies. Language preference may be stored in your browser's localStorage. The interactive demo loads map tiles from Esri, fonts from Google Fonts, the MapLibre library from a CDN (jsDelivr), and optional driving routes from the public OSRM demo server. Those providers may process your IP address as a normal web request. If we later add analytics, we will update this policy and, where required, ask for consent.
11. Automated decisions
We do not use your personal data for automated decision-making that produces legal or similarly significant effects about you (no credit scoring, no automated bans based solely on profiling).
12. Changes
If we change this privacy policy, we will update the date at the top. For significant changes, we will provide a notice in the app where reasonable.
13. Contact
Questions about this privacy policy? Email
support@tripsphere.eu.