HeyTripper — Privacy Policy
Last Updated: 17 Aug 2026
1. Introduction
This Privacy Policy explains how Yechan Park ("HeyTripper," "we," "us," or "our") handles information in connection with the HeyTripper mobile application (the "App") and the HeyTripper website at heytripper.com (the "Website"). We built HeyTripper to work with as little personal data as possible: there is no account system requiring your name or email, and no advertising SDKs. The App does use limited product analytics and keeps a record of search activity, tied to an anonymous identifier rather than your identity — see Sections 2.2, 2.6, and 4 for details. Most of what the App remembers about you stays on your device; the exceptions are described in those sections.
2. Information We Collect
2.1 Location Data
If you allow it, the App reads your device's GPS location (via the
geolocator package, requesting "when in use" / foreground location
permission only — never background/always location) to power the "Nearby"
search mode. Your coordinates are:
- Used on-device to build a search request.
- Sent to Google's Places API and Geocoding API as part of that request, so Google can return places near you.
- Not stored by us anywhere — we have no server to store it on. Google processes it as described in Section 4.
You can deny or revoke location permission at any time in your device settings; the App falls back to manual text-based location entry.
If you save a place found via GPS search, that place's coordinates (not your personal location) are stored locally as part of your saved-places list — see Section 2.3.
2.2 Search Input and Preferences
- Search queries: the mood, category, or free-text description you enter to search for a place. This is sent to Google's Gemini API (to plan the search) and Google's Places API (to find matching places). We also keep a record of the query text, whether the search succeeded or failed, and — for successful searches — the Google Place ID and AI-generated description/memo suggestion for each result, in a database we operate (see Section 2.6). We never record the place's name, photo, or Google Maps link in that database. This record is linked to an anonymous identifier, not to your name or email.
- Language preference: the display language you choose in Settings, stored locally on your device.
2.3 Saved Places ("My List")
When you save a place, the App stores the following locally on your
device only (via SharedPreferences, not on any HeyTripper server):
- The place's Google Place ID and coordinates.
- Any memo you write (or an AI-drafted memo you choose to keep) for that place.
- The last time the place's location was refreshed.
We do not store photos of saved places on your device or on any server — a prior version of the App briefly cached place photos locally, but this was removed to comply with Google Places API policy (no persistent caching of Places content), and any leftover cached files from that version are automatically deleted on app update.
2.4 App Usage Counters
To enforce the daily free-search limit, the App stores a search count and
the date it was last reset, locally on your device (SharedPreferences).
This counter never leaves your device and is not linked to any identity.
2.5 Information You Choose to Provide
If you tap "Send Feedback" in Settings, the App opens your device's email app pre-addressed to us; whether you send that email, and what you write in it (including your email address, which your mail app fills in automatically), is entirely up to you. We only receive what you choose to send.
If you use the Website contact form, you may choose to send us your name, email address, and message. We use that information only to respond to your inquiry. We do not use it for advertising or sell it to third parties.
2.6 Analytics and Anonymous Identifier
The App uses Firebase Analytics and a database we operate (via Supabase) for limited product analytics:
- Anonymous identifier: the first time you open the App, it creates an anonymous account with our backend provider (Supabase) — no name, email, or password involved. This generates a random ID stored on your device, used only to link the search records described in Section 2.2 together. We cannot use it to identify you personally.
- Category selection: when you tap a mood/category card on the Home
screen and start a search, we log which category you picked (event name
category_selected) via Firebase Analytics, so we can see which categories people actually use. This event does not include your search text or location. - Search records: as described in Section 2.2, we keep a record of search queries and results (Place ID and AI-generated description only) linked to your anonymous identifier, so we can review what people search for and improve how the App matches results.
We do not use advertising SDKs or crash-reporting SDKs, and we do not build cross-app or cross-site tracking profiles, sell this data, or use it for advertising. If what we collect changes materially in a future version, we will update this Policy and, where required by law, request your consent.
3. How We Use Information
Because nearly all of the data described above is processed and stored on your device rather than sent to us, "how we use it" mostly describes how the App, running on your device, uses it:
- To find and display places matching your search.
- To show your saved places on the map and in lists, grouped by country.
- To enforce the daily free-search limit.
- To remember your language preference.
- To respond to feedback or contact-form messages you voluntarily send us.
4. Third-Party Service Providers
HeyTripper relies on the following third-party services to function. When the App contacts these services, the data described above (your search input, and — for Nearby mode — your coordinates) is sent directly from your device to that provider, governed by that provider's own privacy policy:
| Service | Purpose | Data sent | Provider policy |
|---|---|---|---|
| Google Places API / Geocoding API | Find real places matching your search | Search text, coordinates (Nearby mode only) | Google Privacy Policy |
| Google Maps SDK | Render the map in the App | Coordinates of your saved places (to draw pins) | Google Privacy Policy |
| Google Gemini API | Interpret your search input and draft short descriptions | Search text | Google Privacy Policy |
| Firebase Analytics (Google) | Understand which mood/category selections lead to a search | Category selected, general app usage events | Google Privacy Policy |
| Supabase | Anonymous authentication; stores the search records described in Section 2.2/2.6 | Anonymous user ID, search query text, Place ID and AI-generated description of results | Supabase Privacy Policy |
We do not control, and are not responsible for, how Google processes data once it receives your request. Per Google's Places API data policy, we do not persist Places content (names, photos, reviews) on any server we operate — the only Places-derived data that persists anywhere is what's saved locally on your own device, as described in Section 2.3.
We do not sell your information, and we do not share it with advertisers or data brokers.
5. Data Storage, Location, and Retention
- Your saved places, search-count limits, and language preference remain
local-only — stored on your device via
SharedPreferences, never on a server we operate. This is included in your device's normal app-data backups if configured to back up app data (iCloud/Android backup), which are managed by Apple/Google, not by us. It is retained until you delete it (e.g., unsaving a place) or uninstall the App, at which point it is permanently removed — we have no way to recover it, because we never had a copy. - Location history is never stored anywhere, by us or otherwise — see Section 2.1.
- The search records described in Sections 2.2 and 2.6 (query text, Place ID and AI-generated description of results, linked to an anonymous identifier) are stored in a database we operate on Supabase's infrastructure. Because this record isn't linked to your name, email, or any account, we have no way to look up which anonymous record belongs to you from a request alone. Contact us (Section 11) if you'd like guidance on this.
6. Your Rights and Choices
- Location permission: grant or revoke at any time via your device's OS settings.
- Delete saved places: remove any saved place directly in the App at any time (My tab → unsave).
- Erase all local data: uninstall the App, or clear its storage/data via your device's OS app settings.
- Access/portability/deletion requests regarding data held by us: since we do not hold your data on a server, most requests are self-service via the App or device settings above. If you believe we hold information about you that isn't covered by this (e.g., an email you sent us), contact us at the address in Section 11 and we will respond as required by applicable law (including GDPR for users in the EU/EEA/UK and CCPA/CPRA for California residents, where applicable).
- California residents: we do not sell or "share" (as defined by the CCPA) personal information, and have not done so in the preceding 12 months.
7. International Data Transfers
Because your device communicates directly with Google's global infrastructure (Section 4), your search input and, in Nearby mode, your coordinates may be processed in countries other than your own, subject to Google's safeguards and privacy policy.
8. Children's Privacy
The App is not directed to children under the age of 14, and we do not knowingly collect personal information from children. If you believe a child has used the App in a way that concerns you, contact us and we will take appropriate steps.
9. Security
Because most data stays on your device, its security depends significantly on your device's own security (passcode, OS updates, etc.). We use industry-standard practices (e.g., HTTPS) for the data your device sends to Google's APIs, but no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy as the App evolves — for example, if we introduce Search Pass payments, account features, or expand what we collect for analytics. We will update the "Last Updated" date above and, for material changes, provide additional notice (e.g., an in-app notice) before the change takes effect.
11. Contact Us
Questions about this Privacy Policy, or requests regarding any information you've sent us, can be directed to:
Email: ychic1109@gmail.com
Company: Hey Tripper
