Privacy Policy
Last updated: August 13, 2026
Information we handle
tabibi (the “App”) handles the email address needed to identify an account, external authentication identifiers from Google or Apple, an optional display name, password hashes, profile images, plans and idea boards you create, spots and schedules in plans, notes, attachments, lists, and reservation candidates.
For inquiries, we handle your question or submission, the AI's answer, and an optional reply-to email address. To prevent abuse, the IP address used to submit a form is handled as a hash; the raw IP address is not stored.
Purposes and storage
We use this information for authentication, saving, syncing, and sharing plans, providing and maintaining the App, responding to inquiries, improving quality, preventing abuse, and protecting rights. We do not use it to deliver advertising or to train the App's own AI on user input.
Accounts, plans, and inquiry records are stored in Cloudflare D1. Profile images and note attachments are stored in Cloudflare R2. The device stores a cache for display and offline use.
AI features and disclosures
For AI help inquiries, after you confirm before sending, we send your question to Cloudflare Workers AI to generate an initial answer. The question and answer are stored as an inquiry record for support, quality improvement, and abuse response.
When you run place extraction or plan suggestions, we send the plan or idea-board notes, text from images, checklist items, and other information needed for the feature to Cloudflare Workers AI. The feature input and AI answer are not stored in the App's D1, R2, or application logs unless you review and save the content.
Cloudflare has published that it does not use Workers AI customer content to train AI models or improve its services without explicit consent. See Cloudflare's data usage policy for details.
Location and maps
We access the device's location for the current-location display on the map only when you grant permission. tabibi does not send or store location data on its servers.
In-app maps, place search, and route guidance use Apple MapKit. Apple may receive search places, routes, or location information in connection with map and route searches. When you choose to do so, the App passes destinations or route information to Apple Maps or Google Maps to open the external app.
External authentication and sharing
For Google Sign-In, the server verifies the ID token received from Google (a temporary proof used to verify the authentication result) and may receive the email address and display name needed for authentication. The App does not obtain your Google Account password and does not store Google's refresh token (the credential used to refresh a sign-in).
When you sign in with Apple, we may receive an Apple-provided identifier that links your Apple account to your tabibi account (a value issued per Apple development team and separate from your email address), the email address Apple provides as verified, and the name you provide on Apple's authentication screen. We use the Apple identifier instead of an email address to recognize you when you sign in again.
- If Apple provides a name on the first sign-in, we save it as the display name for the new tabibi account. If no name is provided, we do not save one.
- On later sign-ins, we match the existing account by the Apple identifier. We do not remove or replace the display name saved on the first sign-in merely because Apple does not provide the name again.
- If you choose “Hide My Email,” we use the relay address issued by Apple (for example,
@privaterelay.appleid.com) as the email address received. tabibi does not guess or replace your original email address. - If Apple does not provide a verified email, we may use an internal substitute so that an account can still be created with the Apple identifier. This is not an estimate of your original email address.
For Apple's rules about information sharing, Hide My Email, and subsequent sign-ins, see Apple's official Sign in with Apple documentation and its private email relay documentation.
When you share a plan, the invited person can see the plan name, schedule, and the inviter's display name or email address. Plans that you have not shared are not shown to other users.
Retention and deletion
We retain account-linked information and AI inquiry records while the account is active for the purposes above. Deleting the account from the Settings screen opened from the icon at the top right of the App deletes authentication information, plans and idea boards you own, their saved information (spots and schedules, notes, attachments, lists, and reservation candidates), participation in shared plans, and AI inquiry records.
tabibi session access tokens and refresh tokens are stored on the device in Keychain (the iPhone's protected storage), while the server stores only a hash of the refresh token. For Apple's refresh token (the credential used to refresh a sign-in and unlink Apple), the server stores only an encrypted value protected by a dedicated server key. Apple's ID token, one-time authorization code, and nonce (the temporary value linking an authentication request to its result) are handled temporarily for authentication and are not stored as account information.
Logging out ends the tabibi session. When you delete your account, if an Apple refresh token is stored, we ask Apple to revoke it and then delete tabibi's authentication information containing the Apple identifier, email address, display name, and encrypted refresh token. The tabibi account and related data are deleted even if Apple's revocation does not complete. This does not delete the Apple account itself.
For Apple's approach to deleting authentication information and revoking tokens, see the official Apple token revocation documentation.
The unauthenticated inquiry form is not linked to an account and is retained only as long as necessary for responding to inquiries, quality improvement, abuse prevention, and rights protection. Contact the channel below if you want to request disclosure or deletion of a form submission.
Contact
Please contact us through the support channel listed on tabibi's App Store page.