1. Scope and operator
This Privacy Policy applies to the TripCost iOS app, its home-screen widget, and this website. TripCost is a free true travel cost assistant operated by an independent TripCost developer.
TripCost does not require an account and does not ask for your name, phone number, or email address to use its core features. We do not read or store full payment card numbers, expiration dates, CVV or security codes, bank credentials, identity documents, text messages, or email.
This policy describes the actual data handling in V1.0. If account, analytics, notification, or other connected features are added later, we will update this policy and any required consent disclosures before enabling them.
2. Information we handle
“Handle” includes storing, reading, calculating, or exporting information on your device, and sending it to a relevant service only when you enable the related feature.
| Category | Examples | Default location | When it leaves the device |
| Trips and budgets | Destination, dates, budget, and trip name | On-device database | Only to your private CloudKit database after you enable iCloud sync |
| Expenses and payment rules | Amounts, currencies, category, merchant notes, payment method name, card network, billing currency, fees, cashback, and final posted amount | On-device database | Structured records sync only after you enable iCloud; full card numbers, CVV, and bank credentials are not included |
| Receipts and scans | Price tags, menus, receipts, or bills you capture or select, plus OCR candidates and recognized text | Device memory, temporary storage, or the app's private directory | Original images and OCR content are not uploaded and do not enter CloudKit |
| Rate and currency queries | Base currency, quote currency, date, rate source, and cache time | On-device cache | Currency and date parameters go to Frankfurter for online refresh; network providers may process standard connection data such as IP address and User-Agent |
| Settings and sync metadata | Default currency, language, refresh interval, favorites, sync setting, record versions, conflicts, and deletion markers | On-device database | Necessary structured settings and sync metadata enter CloudKit after sync is enabled; some device-local preferences are excluded |
| Widget summary | A minimal summary of the selected currency pair, reference rate, budget, and recent expenses | On-device App Group file | Read only by the TripCost widget on your device; not sent to third parties |
| Exports and backups | CSV, PDF, and JSON backup files you create | On-device temporary directory | Only after you choose a destination in the iOS share sheet |
Network connection data
Any internet request can expose an IP address, request time, device network information, and request path to the server or its network provider. TripCost does not attach an account identifier, receipt image, trip, expense record, or payment rule to a rate request.
3. How information is used
TripCost handles information only to:
- perform currency conversion, expression calculation, payment-cost comparison, and DCC markup checks;
- recognize prices, receipt text, and candidate amounts on device with Apple Vision;
- create and show trips, budgets, expense records, final-posting reconciliation, and historical snapshots;
- cache or refresh daily reference rates according to your settings and provide the latest cache offline;
- sync structured data across devices on the same Apple Account when you enable CloudKit sync;
- refresh the on-device widget or create, share, back up, and restore data at your request; and
- maintain data integrity, resolve sync conflicts, and prevent stale records from overwriting newer ones.
TripCost does not use this information for advertising, cross-app tracking, profiling, credit scoring, data sales, or training third-party AI models.
4. Third-party services, sharing, and disclosure
TripCost does not sell personal information. The following services participate only when a feature requires them:
- Apple Vision: performs OCR on your device. Using Vision does not upload the image to a TripCost server.
- Apple iCloud / CloudKit: stores structured data in your private CloudKit database after you enable sync in the app. CloudKit processing and safeguards are governed by Apple's Privacy Policy.
- Frankfurter and Cloudflare: online rate requests go to the Frankfurter public API. Frankfurter states that its API itself does not collect personal data, but that its public service uses Cloudflare, which may process standard network information for security, performance, and basic analytics. Their respective policies govern that processing.
- Share destinations you choose: when you export a CSV, PDF, or backup through the iOS share sheet, you choose the recipient app, person, or cloud service. That recipient then handles the file under its own policy.
We may disclose necessary information where required by law, to protect users or the public, or in response to valid legal process. However, because core TripCost data stays on device by default and developers cannot view users' private CloudKit database content in the Developer Portal, we generally do not possess the core ledger data to disclose.
5. System permissions
- Camera: requested only when you choose to scan with the camera, to capture and recognize a price tag, menu, receipt, or bill on device.
- Photos: requested only when you choose to import from your photo library, to read the image you explicitly select and recognize it on device.
- iCloud: CloudKit is accessed only after you enable structured-data sync. Local entry and viewing continue to work when iCloud is unavailable.
V1.0 does not require location, contacts, microphone, notifications, or App Tracking Transparency permission. If you decline camera or photo access, you can still enter amounts and expenses manually. You can change permissions at any time in iOS Settings.
6. Data retention and deletion
- On-device database and receipts: retained until you delete a record, use “Clear receipt images” or “Clear all data,” or uninstall the app. Copies in a system backup may remain under Apple's backup retention rules.
- Widget summary: updated with the main app and removed before the local database when you use “Clear all data,” so stale accounting information is not left on the widget.
- CloudKit data: retained in your Apple Account's private database until you delete third-party app data through iCloud storage management or Apple deletes it under its rules. Turning off sync in TripCost stops future sync but does not automatically erase information previously stored in iCloud.
- Exports and backups: retained according to the location and recipient you choose. TripCost cannot control copies you have already shared.
- Rate-service logs: may be retained by Frankfurter or Cloudflare under their security and operations policies. TripCost does not control their exact retention periods.
“Clear all data” removes the local database, receipt files, sync state, and widget summary. If you previously enabled iCloud sync, also review and delete TripCost cloud data in Settings > [your name] > iCloud > Storage / Manage Account Storage. Labels may vary by iOS version.
7. Your controls and rights
You can use the app or system settings to:
- view, edit, and delete trips, expenses, payment methods, and settings;
- export CSV or PDF files or create a JSON backup to obtain a copy of your data;
- clear receipt images separately or clear all on-device data after a two-step confirmation;
- turn off iCloud sync, or stop TripCost from using iCloud in iOS iCloud settings;
- withdraw camera and photo permission while continuing to use manual entry; and
- review and delete a third-party app's iCloud data through iCloud storage management.
Apple states that users own content in their private CloudKit databases and, by default, only the user can access it; developers cannot view this private content in the Developer Portal. You can also contact us at the address below with questions about this policy, data flows, or a privacy action you cannot complete yourself.
8. Security, storage location, and international processing
TripCost uses data minimization, local-first storage, the operating system sandbox, just-in-time permissions, and separation of structured sync data. CloudKit uses Apple Account authentication and protections in transit and at rest. However, no electronic storage or transmission method can be guaranteed absolutely secure.
On-device data resides on your Apple device. If you use iCloud or online rates, Apple, Frankfurter, Cloudflare, and their infrastructure may process data outside your country or region. Those services apply safeguards under their own privacy policies and applicable laws. Avoid entering unnecessary sensitive personal information in free-text fields such as merchant notes.
9. Children's privacy
TripCost is intended for general travelers and is not directed specifically to children. It does not ask users for age or identity details. We do not knowingly collect a child's name, contact information, or account details. If you believe a child added unnecessary information to a free-text field or export, delete that record on the device or contact us for guidance.
10. Data handled by this website
This is a static website with no accounts, forms, or payment features. It uses no advertising, analytics service, tracking pixel, or external font. The language switch stores one localStorage key solely to remember your Chinese/English preference. The website sets no tracking cookie.
A hosting provider may process standard server logs such as IP address, access time, User-Agent, and request path to deliver the site, provide security, and troubleshoot. Once a production host is selected, this page should identify the host and link to its privacy policy.
11. Changes to this policy
We will update this policy when important changes occur in features, third-party services, data handling, or legal requirements. We will revise the effective date and version number above. If a change materially affects your rights, we will provide an appropriate notice in the app or on this website and obtain renewed consent where required.