Privacy Policy
Last updated: September 1, 2026
This Privacy Policy explains how Grptripz (“Grptripz,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use the Grptripz mobile application and website (together, the “Service”). Grptripz helps groups plan trips together — itineraries, shared expenses, group chat, photos, and settling up. By using the Service, you agree to the practices described here.
Contents
1. Information we collect
Information you provide
- Account information: your email address, display name, phone number, and (optionally) a profile photo. Authentication is handled by Google Firebase Authentication; we do not store your password. Your phone number is stored so that friends who import your number from their contacts can be matched to your account.
- Trip content: trips you create or join, itinerary events, expenses (amounts, descriptions, currency, who paid, and how costs are split), settlements, checklists, and your friends list.
- Photos and moments: images and captions you add to a trip’s shared timeline.
- Messages: chat messages, reactions, and polls you send within a trip.
- Receipts: images of receipts you choose to scan (see Receipt scanning).
- Payment handles: usernames you optionally add for settling up (e.g., Venmo, Cash App, PayPal, or Zelle). These are identifiers you enter — not card or bank account numbers — and we do not process payments (see Payment handles).
- Contacts: if you choose to add friends from your address book, the app asks for contacts permission and shows you a list of your contacts to pick from. Only the contacts you explicitly select are uploaded. We do not upload your address book, and we do not read it unless you start this flow. For a contact you select, we store their name, email address, and phone number in your friends list, and we use that email address and phone number to check whether they already have a Grptripz account so we can connect you. This is information about other people, who may not use Grptripz themselves, so please only import contacts you have a reason to add.
Information collected automatically
- Device & push tokens: a push notification token and device/platform information so we can deliver notifications you’ve enabled. Notifications are delivered through Expo’s push service, which receives the token along with the title and body of each notification (see Service providers).
- Diagnostics & crash data: we use Sentry to monitor errors and stability. This includes technical event data and, by default, your IP address and approximate location derived from it.
- Usage data: limited counters and events about how features are used (for example, number of receipt scans) to operate, secure, and improve the Service. We use Firebase Analytics to help us understand feature usage. These analytics events are associated with your account identifier rather than collected anonymously.
2. How we use information
We use the information above to:
- Provide and operate the Service — create and sync trips, expenses, balances, itineraries, chat, and photos across the members of a trip;
- Calculate balances and suggested settlements;
- Send notifications you’ve enabled (e.g., itinerary reminders, settlement requests, new activity);
- Extract details from receipts you choose to scan, and answer your questions or read booking confirmations when you use the AI features;
- Maintain security, prevent abuse, debug, and improve reliability and features;
- Manage subscriptions and entitlements; and
- Communicate with you about the Service and respond to your requests.
3. Sharing with trip members
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
4. Service providers
We rely on a small number of trusted providers who process data on our behalf, under their own terms and privacy commitments:
- Google Firebase (Authentication, Cloud Firestore, Cloud Storage, and Cloud Messaging) — our core backend, database, and file storage.
- Expo — push notification delivery. Your device sends notifications through Expo’s push service, which relays them to Apple and Google. Expo receives your push token and the content of each notification, which can include member names, expense descriptions, and chat message previews.
- Sentry — error monitoring and diagnostics, including the technical data described above.
- RevenueCat — subscription and in-app purchase management. RevenueCat receives an account identifier for you and your purchase history, including which product you bought, from which store, and when it renews or expires. When you buy a Trip Pass, a trip identifier is attached so the purchase can be applied to the right trip.
- Anthropic — the model provider behind our AI features. See AI features for what is sent.
- Receipt scanning provider — a third-party service used to read details from receipt images you submit. We use TabScanner and Google Cloud Vision for this.
- Resend — delivery of trip invitation emails. Resend receives the email address you are inviting, along with your display name and the trip name, so the invitation can be sent. The person you invite may not be a Grptripz user.
- Google Places, Geoapify, and Pexels — place lookup and cover images. When you type a destination or a place name, that text is sent to Google Places or Geoapify to return suggestions, and a destination may be used to search Pexels for a trip cover photo. These lookups are not tied to your account, and we do not keep a history of them.
- Currency exchange data — a provider of foreign-exchange rates used to convert expense amounts. We use ExchangeRate-API (exchangerate-api.com).
- Apple App Store and Google Play — app distribution and any in-app purchases.
5. Receipt scanning
If you use receipt scanning, the receipt image you capture is sent to our receipt-processing provider to extract details such as the total, merchant, and date, which are then pre-filled into a new expense for your review. You can always enter expenses manually instead. The image is sent for processing without your name, email address, or account identifier attached.
Receipt images you save are stored with the trip they belong to, and they stay there for as long as that trip’s data exists. Removing a trip inside the app archives it and does not by itself delete the stored images. Receipt images are deleted when the trip’s stored data is deleted, which happens when you delete your account and no other member remains on that trip. On a trip with other members, the trip’s content stays with the group (see Retention & deletion).
6. AI features
Grptripz includes optional AI features: Ask Grptripz, which answers questions about a trip you are a member of, and booking import, which reads a booking confirmation you paste in and turns it into an itinerary event. Both are powered by Anthropic. If you do not use these features, nothing is sent.
When you ask a question, we send a summary of that one trip so the answer can be grounded in it. That summary can include the trip name and destination, the display names of its members, expense descriptions and amounts, itinerary events including locations, notes, and booking confirmation numbers, checklist items, and calculated balances. For booking import, we send the confirmation text you provide.
Some information is deliberately withheld and never sent: members’ email addresses and phone numbers, trip invite codes and invite links, and the links to your stored receipts and attachments. Your account identifier is not sent either, so the request is not tied to your identity at the provider.
7. Payment handles & subscriptions
Grptripz helps you track who owes what, but we do not move money or process payments. When you settle up, you do so directly through your own payment apps (such as Venmo, Cash App, PayPal, or Zelle). The payment handles you add are stored only so they can be shown to other members of your trips for convenience.
Paid subscriptions, if you purchase one, are processed and billed by the Apple App Store or Google Play in accordance with their terms. We receive your subscription status to unlock features, but we do not receive your full payment card details. We use RevenueCat to manage subscriptions and entitlements, so RevenueCat receives an account identifier for you and your purchase history (see Service providers).
8. Retention & deletion
We keep your information for as long as your account is active or as needed to provide the Service. You can delete your account at any time from within the app, or via grptripz.app/delete-account.
When you delete your account, we delete or de-identify your personal account information. Note that content you contributed to a shared trip (for example, an expense you added that affects other members’ balances, or a message you sent) may remain visible to the other members of that trip so their records stay intact, even after your account is removed.
The same applies to stored files. When you delete your account we delete your profile photo, and for any trip where you were the only remaining member we delete that trip’s stored files, including its photos, receipts, chat attachments, and itinerary attachments. On a trip that still has other members, those files stay with the trip so the group keeps its records.
9. Security
We protect your information using industry-standard measures, including encryption in transit (HTTPS/TLS) and access controls enforced by server-side security rules. No method of transmission or storage is 100% secure, but we work to protect your information and to promptly address issues we become aware of.
10. International data transfers
Grptripz is operated using infrastructure that stores and processes data primarily in the United States. If you access the Service from outside those countries, you understand your information may be transferred to and processed there. Where required, we rely on appropriate safeguards for such transfers.
11. Children
The Service is not directed to children under 13 (or the minimum age required in your country, such as 16 in parts of the EEA), and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
12. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. You can exercise many of these directly in the app (editing your profile, deleting content, or deleting your account), or by contacting us. We will not discriminate against you for exercising your rights.
You can turn off push notifications at any time in your device settings or in the app.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we’ll revise the “Last updated” date above and, where appropriate, notify you in the app. Your continued use of the Service after changes take effect means you accept the updated policy.
14. Contact us
If you have questions about this Privacy Policy or your information, contact us at hello@grptripz.com, operated by Grptripz LLC.