Privacy Policy
Last updated: 2026-08-13
Version 2.2This policy explains what Ntripi collects, why, who else sees it, and how long we keep it.
1. WHO WE ARE
Ntripi is the operator of this service and the controller of the personal data described here. For any question about your data, or to exercise any of the rights in section 11, write to [email protected].
2. INFORMATION WE COLLECT
Account: your email address, your chosen username, your display name, your date of birth, and — if you set a password — a bcrypt hash of it. We never store your password in plain text. If you sign in with Google we store the identifier Google gives us for your account, and the profile name and picture Google supplies.
Your date of birth: we ask for it once, when you create your account, to check that you meet our minimum age. If you sign in with Google and grant the permission, we read it from your Google profile instead; you can refuse that permission and type it in yourself. It is never shown on your profile and never visible to other users. We record whether it came from Google or from you, so that we can answer questions about how an account's age was established.
Content you create: itineraries, stop names, addresses, notes, annotations, transport details, ratings and reviews, and the photos you upload.
Location you choose to enter: the coordinates of the stops you add. Ntripi does not track your device's location; a coordinate is only stored because you searched for a place, picked it on the map, or typed it in.
Technical data: your IP address at the time of a request, and your device and app details when you send a bug report.
Moderation and safety records: reports you file or that are filed about your content, and the outcome of any moderation decision affecting you.
3. HOW WE USE IT
To run your account and show your content to the audience you chose.
To check that you meet our minimum age, and to keep under-age accounts off Ntripi.
To keep Ntripi safe: automated and human review of content, handling reports, enforcing the Community Guidelines, and appeals.
To email you about your account — verification, password reset, and moderation notices. We do not send marketing email.
To fix problems you report to us.
4. AUTOMATED CONTENT MODERATION
Content you publish is checked automatically before it becomes visible, using services run by other companies.
Text — itinerary titles and descriptions, stop names, addresses and notes, annotations, transport details, review notes, your display name and bio, and the username and name you choose at registration — is sent to OpenAI's moderation service. The request carries the text and the name of the model, and nothing else: no account identifier, no email address, no content identifier. OpenAI cannot tell whose text it is.
Photos are sent to Amazon Web Services' Rekognition service to be checked for explicit and violent imagery. Only the image is sent.
Images are stored and served through Cloudflare, which scans images served from our domain against known-illegal-image databases at the point they are served.
Where a check is unavailable, content is stored and queued for review rather than blocked.
We keep the verdict of a moderation check in a short-lived cache. The cache stores no raw text and no reference to the person who wrote it.
5. WHO ELSE RECEIVES YOUR DATA
We do not sell, rent, or share your personal information with third parties for their marketing purposes. The following process data on our behalf:
Railway — application hosting and the database.
Cloudflare — DNS, the content delivery network, image storage (R2), and the illegal-image scanning described above.
OpenAI — text moderation, as described above.
Amazon Web Services — image moderation, as described above.
Google — sign-in, if you use it. Google receives the fact that you signed in to Ntripi.
OpenStreetMap / Nominatim — address search. The place text you type when adding a stop is sent to Nominatim, and your device requests map tiles from OpenStreetMap while a map is on screen. We do not store your raw search queries.
Have I Been Pwned — when you choose a password we check whether it appears in known breach data. The check sends the first five characters of a hash of your password and nothing else; your password never leaves our server.
Atlassian (Jira) — where we forward a bug report you sent so it can be tracked and fixed. The forwarded ticket carries your description, the screenshot, and the technical details; it does not carry your email address.
Google (Firebase Cloud Messaging) — push notifications on iOS and Android, if you allow them. Your device is issued a registration token that identifies that installation; we store it so we can address a notification to your device, and we delete it when you sign out. The notification text passes through Google to reach your phone: it says what happened and, where relevant, names the person who acted or the title of your own itinerary. Notices about moderation of your content never name who reported it. If you do not grant notification permission, no token is created and nothing is sent.
We also disclose data where we are legally required to, and where it is necessary to respond to an imminent risk to someone's safety.
6. PHOTOS
Photos are resized and re-encoded on upload, and their EXIF metadata — which can contain the GPS coordinates and the time the photograph was taken — is stripped before the image is stored. This happens on our server; the original file is not kept.
7. BUG REPORTS
If you report a problem from inside the app (by shaking your phone or from Settings), we receive a screenshot of the screen you were on, the description you write, and basic technical details: app version, platform, device model, operating system version, the screen you were on, your language, and your light/dark setting. If you were signed in, the report is linked to your account so we can follow up.
We use this only to reproduce and fix the problem you reported, and we may forward it to our issue tracker as described in section 5. Please avoid sending a screenshot that shows information you would rather not share — the screenshot is captured from whatever was on screen. Bug reports and their screenshots are deleted once the report has been resolved and has aged out of our support records.
8. REPORTS, BLOCKING, AND NOTIFICATIONS
When you report content, we store the report, the reason you chose, any note you wrote, and a keyed one-way hash of your IP address — used to stop one person filing the same report repeatedly, and not reversible back to an address. The report is retained even if the content it concerns is later deleted, because it is the evidence for the decision we took. The person you reported is never told who reported them.
When you block someone, we store the fact of the block so it can be enforced in both directions. Unblocking deletes it.
In-app notifications record what happened and who did it, not a written-out message; the text you read is assembled on your device in your language.
9. COOKIES
Signing in does not use cookies — your session tokens are stored on your device and sent only in request headers.
Website pages set a single preference cookie (ntripi_lang) to remember your language choice. It contains no personal data and is never shared with anyone.
If you sign in with Google, Google may set its own cookies as part of its sign-in service; those are governed by Google's privacy policy.
We do not use analytics cookies, advertising cookies, or any third-party tracking scripts.
10. HOW LONG WE KEEP IT
Your account data and content are kept until you delete them, or until you delete your account.
You may delete your account at any time from the app settings. Account deletion permanently removes your profile, itineraries, and identifying information.
Your date of birth is kept for as long as the account exists and is deleted with it. We keep it rather than only the answer it gave us, because the minimum age changes with time and a stored yes or no would silently go stale.
Ratings you have submitted are retained in anonymised form (score only, no user link) to preserve the integrity of community scores. You consent to this when you create your account, as described in our Terms of Service.
Moderation records are deleted after 90 days once the matter is closed, with one exception: where an image matched a known-illegal-image database, the record of the match and the hash of the image are retained indefinitely. The image itself is deleted; the record is the only evidence that the removal happened, and keeping it is a legal duty we cannot waive at your request.
In-app notifications are deleted 90 days after you have read them. Unread ones are kept.
Bug reports and their screenshots are deleted once the report is closed and has aged out.
11. YOUR RIGHTS
You can access, correct, export, or delete most of your data directly in the app: your profile is editable, your content is editable and deletable, and Settings, Delete account removes the account.
Depending on where you live you may also have the right to ask us for a copy of your data, to have it corrected or erased, to restrict or object to how we use it, and to complain to your national data protection authority. Write to [email protected] and we will respond.
We will not suspend or terminate your account in retaliation for exercising any of these rights.
12. CHILDREN
Ntripi is not for children under 16, and we do not knowingly collect data from them. We ask for a date of birth at sign-up and refuse accounts below that age. If you believe a child under 16 has an account, write to [email protected] and we will remove it.
13. INTERNATIONAL TRANSFERS
The services listed in section 5 operate in several countries, so your data may be processed outside the country where you live, including in the United States. Where that happens we rely on the transfer safeguards those providers offer, such as the European Commission's standard contractual clauses.
14. SECURITY
All data in transit is encrypted with TLS. Passwords are hashed with bcrypt before storage. Session tokens are signed and cannot be forged without our server secret key. Access to production data is limited to what is needed to operate the service.
No service is perfectly secure. If we become aware of a breach affecting your data we will tell you and the relevant authority as the law requires.
15. CHANGES TO THIS POLICY
We will update this page when our practices change. The version and date shown with this document tell you which revision you are reading.
16. CONTACT
Questions about your data: [email protected]. To report abuse or a safety concern: [email protected].