TripFumi Privacy Policy
Last updated: August 10, 2026
Effective: August 10, 2026
Quick summary (not part of the policy)
TripFumi is an AI-assisted travel planner published by Zenfumi, Inc. We collect the information needed to provide travel planning, search, trip sharing, notifications, customer support, analytics, security, and service improvement. This can include account information, trip and itinerary content, forwarded travel emails, files, photos, traveler details you choose to save, search parameters, saved flight and lodging details, device data, and analytics events. We do not sell your personal information, and we do not use your User Content to train foundation models for any third party. TripFumi helps you search for flights, hotels, and restaurants and then hands you off to the airline, hotel, travel agency, or restaurant (or its reservation platform) to book or reserve on its own site — TripFumi does not collect your payment card details or complete bookings, and any payment or traveler details you enter at that point are handled by the third party under its own privacy policy.
1. Scope
This Privacy Policy explains how Zenfumi, Inc., a Delaware corporation doing business as TripFumi ("Zenfumi," "TripFumi," "we," "us," or "our"), collects, uses, discloses, and protects personal information when you access or use the TripFumi mobile applications, websites at tripfumi.com and its subdomains, application programming interfaces, notifications, email-ingest features, travel search and booking hand-off features, and related services we provide (collectively, the "Services").
This Privacy Policy is incorporated into the TripFumi Terms of Service. Capitalized terms not defined here have the meanings given in the Terms.
This Privacy Policy does not apply to third-party websites, apps, airlines, hotels, payment processors, ride-share services, travel suppliers, app stores, or other services that we do not own or control, even if they are linked from or integrated with TripFumi. Those third parties handle your information under their own privacy policies.
2. Information we collect
2.1 Account and authentication information
We collect information you provide or that is provided by authentication partners when you create or use an account, such as:
- name;
- email address;
- account identifiers;
- sign-in method, such as one-time passcode, Sign in with Apple, or Sign in with Google;
- authentication metadata needed to keep you signed in and secure;
- profile details, avatar, and settings you choose to add.
We may receive limited profile information from Apple or Google when you choose those sign-in options, subject to your choices with those providers.
2.2 Trip, itinerary, and planning content
We collect the travel information you create, import, upload, forward, or ask TripFumi to generate or organize, including:
- trips, destinations, dates, time zones, notes, preferences, and plan details;
- flights, rail, lodging, restaurants, activities, transportation, rideshare plans, cruise or other travel plans;
- confirmation numbers, booking URLs, vendor names, prices, receipts, and reservation notes;
- lodging details such as property information, brand, check-in and check-out times, room details, and reservation metadata;
- traveler details such as names, emails, phone numbers, home city, home country, and other profile or companion details you choose to store;
- expense records, payment notes between travelers, split details, currencies, categories, and settlement records;
- trip cover images, photos, files, attachments, imported documents, and generated media;
- messages, assistant chats, prompts, and other content you submit to AI-assisted features.
Some travel records may include information about other people, such as co-travelers, friends, family members, or expense participants. You are responsible for making sure you have the right to provide their information to TripFumi.
2.3 Forwarded emails, uploads, and imported content
TripFumi may let you forward travel-related emails, share files, or upload documents. We collect the content and metadata needed to process those materials, such as sender and recipient information, subject lines, message bodies, attachments, MIME metadata, receipt details, booking references, dates, locations, prices, and extracted structured travel data.
Forwarded or uploaded materials may contain personal information unrelated to your trip. Please avoid forwarding or uploading confidential or unrelated information that TripFumi does not need.
2.4 Flight, hotel, and restaurant search information
When you search for flights, hotels, restaurants, or other travel options, we collect and process the information needed to run the search and show you results, such as:
- origin, destination, dates, cabin, guest or passenger counts, location, cuisine, and similar search parameters and preferences;
- the results we retrieve from our search-data provider, such as flight offers, fares, hotel rates, restaurant listings, prices, and availability; and
- the options you choose to save to a trip, and any notes you add to them.
Bookings and reservations are completed on the third party's own website or app after we hand you off (see Section 5.3 and Section 5.4). TripFumi does not collect passenger or guest identity documents, payment card details, or airline or hotel booking records for those transactions; you provide that information directly to the airline, hotel, travel agency, restaurant, or reservation platform, which handles it under its own privacy policy.
2.5 Payment information
TripFumi does not collect, store, or process payment card details for flights, hotels, restaurants, or other travel bookings. Those bookings are completed on a third party's own website or app, and any payment information you enter there is handled by that third party (and its payment processor) under its own terms and privacy policy.
Paid TripFumi subscriptions ("TripFumi Premium") are sold through the Apple App Store or Google Play, which process your payment details under their own terms and privacy policies. We do not receive your payment card details. We use RevenueCat, a subscription-management service, to process purchase and subscription events from the app stores; RevenueCat receives your TripFumi account identifier and subscription state (such as product, trial or paid status, and expiry) so we can provide and reconcile paid features.
2.6 Collaboration, friends, and sharing information
When you use TripFumi's sharing and collaboration features, we collect information such as friend requests, friend lists, invitees, collaborator roles, shared trip IDs, recipient counts, invitation status, blocked-user settings, and content shared between collaborators.
If you share a trip, expense, plan, file, photo, or other content with another user, that content becomes visible to the people you share it with according to the permissions you set. Those people may copy, save, screenshot, or further disclose it outside TripFumi.
2.7 Device permissions and device data
Depending on the features you use and the permissions you grant, we may collect or access:
- Location data, including precise or approximate location, for nearby places, trip context, time zones, weather, ride estimates, maps, and location-aware suggestions;
- Contacts, such as selected contact details or contact-list information, for friend discovery and invitations;
- Calendar data, so TripFumi can write trip plans to your device calendar when you enable calendar sync;
- Photos, camera, and files, for trip covers, attachments, profile images, imported documents, and shared files;
- Notifications, including push tokens and notification preferences, so we can send trip, collaboration, finance, upload, and flight alerts;
- Device and app data, such as device type, operating system, app version, build number, runtime version, update channel, app lifecycle events, and crash diagnostics.
Operating-system permission prompts control access to many of these categories. You can revoke permissions in your device settings, though doing so may disable or degrade the related feature.
2.8 Calendar integration information
If you enable calendar sync, TripFumi writes selected trip and plan details to the calendar database on your device using your operating system's calendar provider. Device-local calendar identifiers, sync timestamps, and event maps are stored locally on that device and are not synced through TripFumi. Calendar events may be stored or synced by your operating system or calendar provider depending on your device and calendar settings.
2.9 Flight status, places, weather, and travel data provider information
To provide flight tracking, candidate matching, status alerts, place lookup, geocoding, time-zone resolution, weather, airport metadata, and related travel features, we may process and send relevant trip details to third-party providers. This may include flight numbers, airline codes, origin and destination airports, travel dates, airport identifiers, place names, addresses, geographic coordinates, and trip timing information. To display approximate currency conversions for expenses, we may also retrieve exchange rates from a third-party exchange-rate service; those requests carry currency codes, not your personal information beyond standard network metadata.
2.10 Rideshare information
TripFumi may help you open a rideshare service with pickup, dropoff, timing, and provider preference prefilled. If you open a rideshare app or web link, the rideshare provider receives the information included in the link and handles it under its own privacy policy.
Where optional price or ETA estimates are enabled, TripFumi may send pickup and dropoff coordinates to a rideshare provider through our backend in order to retrieve estimates. TripFumi does not handle rideshare authentication, dispatch, ride payment, driver assignment, or ride-state management.
2.11 Analytics, diagnostics, and observability information
We collect analytics and diagnostic information to understand product usage, operate feature flags, improve reliability, and debug issues. This may include:
- account ID and, in some cases, account email associated with product analytics;
- events such as sign-in, trip creation, plan creation, sharing, expenses, flight search, hotel search, restaurant search, booking hand-off, assistant usage, and onboarding interactions;
- app environment, update channel, app version, build number, runtime version, platform, and app lifecycle events;
- crash reports, stack traces, error names and messages, performance traces, logs, breadcrumbs, and coarse device or OS metadata;
- mobile session replay on eligible platforms where enabled for debugging.
Our observability systems are configured to avoid default personal-information collection where supported and to redact sensitive data. We do not intentionally log session tokens, OTPs, passwords, secrets, raw email bodies, raw AI prompts, raw model outputs, raw imported files, raw request or response bodies, precise coordinates, push tokens, or raw payment card details.
2.12 Communications and support information
If you contact us, respond to surveys, request support, report a bug, submit feedback, or communicate with us by email or another channel, we collect the information you provide and related metadata, such as contact details, message content, attachments, and support history.
3. How we use information
We use personal information to:
- create, authenticate, secure, and administer accounts;
- provide, personalize, and improve trip planning, itinerary organization, collaboration, expenses, notifications, calendar sync, file handling, and AI-assisted features;
- parse travel emails, receipts, files, and reservation confirmations;
- search for flights, hotels, restaurants, and other travel options, show prices and availability, and let you save options to a trip;
- provide and reconcile paid subscriptions through the app stores, where offered;
- provide flight tracking, flight alerts, candidate matching, airport metadata, weather, places, maps, time zones, ride estimates, and related travel context;
- send transactional, security, support, trip, collaboration, finance, upload, flight-alert, and notification messages;
- operate feature flags, analytics, diagnostics, crash reporting, performance monitoring, fraud prevention, abuse prevention, and service security;
- enforce our Terms, protect users and the Services, comply with law, respond to legal process, and defend legal claims;
- conduct internal research, testing, debugging, and product development;
- communicate with you about changes to the Services, policies, or your account.
4. AI and automated processing
TripFumi uses artificial intelligence and machine-learning systems to power features such as trip planning, chat, itinerary suggestions, reservation parsing, email classification, email segmentation, trip matching, flight-risk or connection-risk inference, and cover-image generation.
To provide those features, we may send your inputs, User Content, attachments, trip context, email content, and related metadata to third-party AI providers, depending on the feature. We use those providers to generate outputs for you, parse content you submit, and operate the Services. Depending on the provider and configuration, requests may be processed under zero-data-retention terms; other providers may retain prompts or responses for a limited period, such as for abuse monitoring, under their API terms. We configure and contract with providers so they do not use your content to train their foundation models.
We do not sell your User Content. We do not use your User Content to train foundation models for any third party. Any future change to this commitment would require your affirmative opt-in and would be disclosed in this Privacy Policy.
AI outputs may be incorrect, incomplete, outdated, biased, or unreliable. You should verify important travel, safety, legal, health, immigration, financial, and booking information with authoritative sources before relying on it.
5. How we disclose information
We disclose personal information as described below.
5.1 Service providers and processors
We disclose information to categories of vendors and service providers that help us operate the Services, including:
- cloud infrastructure, hosting, storage, networking, security, and communications providers;
- AI model and related infrastructure providers;
- travel search and data providers for flights, lodging, restaurants, places, maps, time zones, weather, rideshare estimates, airport information, and currency conversion;
- identity, mobile-platform, app-store, subscription-management, notification-delivery, and app-update providers;
- analytics, feature-flag, experimentation, diagnostics, crash-reporting, performance-monitoring, and debugging providers; and
- customer-support and similar operational providers.
As described in Section 2.5, we currently use RevenueCat for subscription management and entitlement status. RevenueCat receives your account identifier and subscription state.
These providers may process personal information only as needed to provide services to us or as otherwise permitted by their contracts and applicable law. Some providers, such as app stores and rideshare services — and any airline, hotel, travel agency, restaurant, or reservation platform you choose to book with — may also act as independent controllers for parts of the transaction or service they provide directly to you.
5.2 Other users and collaborators
We disclose your information to other TripFumi users when you direct us to do so, such as when you share trips, invite friends, collaborate on plans, participate in expenses, or join a shared trip. The information disclosed depends on the feature and permissions you choose.
If you create a friend-invite link or QR code, anyone who receives the link can see the profile details attached to the invitation (such as your display name and photo) before accepting, and a person who accepts receives the contact details needed to connect with you. Treat invite links like invitations and share them only with people you want to connect with.
5.3 Travel providers you choose to book with
TripFumi does not transmit your payment details or traveler identity documents to airlines, hotels, restaurants, or reservation platforms to complete a booking. When you choose to book or reserve, we hand you off to the third party's own website or app, and you provide the information needed to complete and support the booking — such as traveler details, contact information, and payment information — directly to that third party (and any payment processor or supplier it uses). The third party handles that information under its own terms and privacy policy.
5.4 Third-party integrations you choose
If you choose to connect with or open a third-party service, such as a rideshare app, calendar provider, map provider, app store, airline, hotel, or booking-management website, information may be disclosed to that third party as needed to complete your request. The third party's own terms and privacy policy apply.
5.5 Legal, safety, and business transfers
We may disclose information if we believe it is reasonably necessary to:
- comply with law, legal process, subpoenas, court orders, or government requests;
- enforce our Terms or other agreements;
- protect the rights, property, safety, or security of TripFumi, our users, the public, or others;
- detect, prevent, or investigate fraud, abuse, security incidents, or technical issues;
- support a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar business transaction.
6. No sale or cross-context behavioral advertising
We do not sell your personal information. We do not "share" personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act and California Privacy Rights Act.
We may disclose personal information to service providers, processors, analytics providers, and other operational partners as described in this Privacy Policy. We may also use aggregated or de-identified information for analytics, product improvement, research, and business purposes.
7. Cookies, SDKs, and similar technologies
TripFumi and our providers may use cookies, mobile SDKs, local storage, identifiers, analytics events, and similar technologies to operate the Services, keep you signed in, remember preferences, measure usage, provide feature flags, detect fraud, improve reliability, and debug errors.
For mobile apps, many controls are available through your device settings, app permissions, app-store account settings, and operating-system privacy controls. For websites, browser settings may allow you to block or delete cookies, though doing so may affect functionality.
8. Retention
We retain personal information for as long as reasonably necessary to provide the Services, maintain your account, comply with law, resolve disputes, enforce agreements, protect the Services, and support legitimate business purposes.
Examples include:
- account and trip content is generally retained while your account remains active or until you delete it, subject to backup and legal-retention periods;
- account deletion uses an approximately 30-day grace period during which you can cancel the deletion, after which your data is purged from our systems;
- data-export download links expire automatically (currently after 7 days);
- flight-alert event data is retained for a limited period (currently about 30 days);
- shared content may remain visible to collaborators who already received access, even if you later remove your own copy or delete your account;
- tax, fraud-prevention, dispute, and legal records may be retained longer where necessary or required by law;
- device-local calendar sync state remains on the device unless you disable the feature, delete the local calendar, clear app data, or remove the app, subject to your operating system and calendar-provider behavior;
- analytics, diagnostic, logs, and crash data are retained according to operational needs and provider settings;
- backups are deleted or overwritten on our routine schedules.
When you delete your account, we will delete or de-identify personal information as required by applicable law, except where retention is necessary for legal, security, fraud-prevention, financial, dispute-resolution, or legitimate business purposes.
9. Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These include access controls, authentication, encryption in transit where appropriate, cloud-provider security controls, secret management, logging controls, and redaction practices designed to avoid sensitive information in observability systems.
No method of transmission or storage is completely secure. We cannot guarantee absolute security. You are responsible for protecting your account credentials, devices, and any third-party accounts you connect or use with TripFumi.
10. International transfers
TripFumi is operated from the United States, and our providers may process information in the United States and other countries. These countries may have privacy laws that differ from those where you live. Where required, we use appropriate safeguards for international transfers, such as contractual protections or other mechanisms recognized by applicable law.
11. Your choices and rights
11.1 Account and content controls
You may use the Services to access, edit, export, or delete certain account and trip content. You may delete your account from inside the app or by contacting privacy@tripfumi.com.
You may also manage feature-specific settings, such as notification preferences, trip mutes, quiet hours, calendar sync, sharing permissions, and device permissions.
Product analytics is optional. In the European Economic Area and the United Kingdom (and where we cannot determine your region), analytics is off unless you opt in; elsewhere it is on by default and you can opt out at any time in the app's settings. Your choice is recorded with your account and applied across your devices.
11.2 Device and platform controls
You can use your device settings to manage permissions for location, contacts, calendar, notifications, photos, camera, files, and similar device features. You can manage app-store subscriptions through your app-store account. You can manage third-party identity, rideshare, airline, hotel, restaurant, booking, and calendar services through those services directly.
11.3 Privacy requests
Depending on where you live, you may have rights to:
- know or access the personal information we collect about you;
- request correction of inaccurate information;
- request deletion of personal information;
- receive a portable copy of certain information;
- restrict or object to certain processing;
- withdraw consent where processing is based on consent;
- opt out of sale or sharing for cross-context behavioral advertising;
- appeal a denied privacy request where applicable;
- not be discriminated against for exercising privacy rights.
To exercise privacy rights, contact us at privacy@tripfumi.com. We may need to verify your identity before responding. If you submit a request on behalf of another person, we may require proof of authorization.
12. California notice
The categories of personal information we may collect are described in Section 2. They may include identifiers, customer records, commercial information, internet or electronic network activity, geolocation data, sensory or media content, professional or travel-related information you provide, inferences, and sensitive personal information such as account credentials and precise location when enabled.
We collect, use, and disclose these categories for the purposes described in Sections 3 and 5. We retain them as described in Section 8.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics about you. We use sensitive personal information only as reasonably necessary to provide the Services, maintain security, comply with law, and support the purposes described in this Privacy Policy.
13. Legal bases for EEA, UK, and similar jurisdictions
Where applicable law requires a legal basis for processing personal information, we rely on one or more of the following:
- Contract, to provide the Services, create and manage accounts, provide support, and enforce our Terms;
- Consent, where you grant device permissions, connect optional integrations, enable certain notifications, submit optional information, or where consent is otherwise required;
- Legitimate interests, to improve, secure, debug, measure, and operate the Services, prevent fraud and abuse, communicate with users, and develop new features;
- Legal obligations, to comply with law, tax, accounting, dispute, travel, payment, and regulatory requirements;
- Vital or public interests, in rare cases where necessary to protect safety or respond to emergencies.
14. Children's privacy
TripFumi is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it. If you believe a child under 13 has provided personal information to TripFumi, contact us at privacy@tripfumi.com.
Users under the age of majority in their jurisdiction may use the Services only with the consent and supervision of a parent or legal guardian, as described in the Terms.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice, such as by in-app notice, email, or updating the date at the top of this page. Your continued use of the Services after the updated Privacy Policy becomes effective means that you acknowledge the updated policy.
16. Contact
For privacy questions or requests, contact us at:
- Privacy:
privacy@tripfumi.com - General support:
support@tripfumi.com - Legal notices:
legal@tripfumi.com
Mailing address for privacy and legal notices:
Zenfumi, Inc.
Attn: Privacy
8 The Green
Suite B #8151
Dover, DE 19901
United States of America