Privacy

Privacy Policy

Last updated: September 14, 2026

Google user data, in short

If you connect a Gmail account, Tripmojo requests read-only Gmail access (gmail.readonly) and uses it for two things: finding your travel-booking confirmation emails and importing those bookings into your trips, and finding reward points statements so your points and miles balances stay current in Tripmojo. Statements from card issuers are only ever read if you separately say yes. We store the extracted booking details, the source booking emails, and your points balances; we never send you ads based on your email, never sell it, and no humans read it except with your consent or for security/abuse investigations. Disconnect any time in Settings. Full details in Section 4.

Tripmojo’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

1. Who we are

Tripmojo and Airport Mojo (“we,” “us,” or “our”) are travel apps operated by Candle Studios LLC (Washington, USA). Tripmojo organises booked trips; Airport Mojo provides airport, lounge, live-flight, and airport-place information. This Privacy Policy covers both apps and the tripmojo.ai website. It explains what personal information we collect, why we collect it, how we use it, who we share it with, and the choices you have.

If you have questions, contact us at contact@tripmojo.ai.

2. Information we collect

  • Account information. When you create an account we collect your email address. If you sign in with Google or Apple, we receive your email and name (Apple may give you a relay email via Hide My Email), and a profile picture where provided.
  • Profile and preferences.Optional details you add - display name, home city, home currency, traveler type, budget preference, dietary preferences, interests, trip vibes, and places you’ve visited - used to personalise suggestions.
  • Trip content. Destinations, dates, travelers, bookings (flights, hotels, activities, restaurants, transit), itinerary items, expenses and who owes whom, comments you add to plan items, and any photos or notes you add.
  • Public contributions. Ratings, reviews, display names, and photos you choose to post about airport places. We show approved contributions to other users and process them for moderation, abuse prevention, and reports.
  • Travel documents you upload.Booking confirmations, boarding passes, and e-tickets, plus anything you choose to store in your Wallet. Wallet documents can include sensitive information such as passports, visas, driver’s licenses, IDs, insurance, and vaccination or health certificates. We store what you choose to upload; please only add documents you’re comfortable storing with us.
  • Booking emails. If you forward a booking email to your Tripmojo inbox address, or connect a Gmail account (see Section 4), we receive and process those emails - including their attachments - to build your trips. Forwarded emails are archived so we can re-read them if extraction needs to be re-run.
  • Device location (optional).If you grant permission, the app uses your device’s approximate location to suggest nearby places. This happens on your device to fetch suggestions; we don’t store your device location on our servers. Coordinates we do store are for places you add to a trip (e.g. a hotel or activity).
  • Notifications. If you enable push notifications, we store a device push token so we can send you trip updates.
  • Usage, analytics, and diagnostics. We collect feature-usage events, screen views, app performance, and crash reports (see Section 7), plus standard log data such as IP address, device/browser type, and timestamps, to operate, secure, and improve the service.

We do not receive or store complete payment card or bank account numbers. If you buy an eSIM or another paid product in Airport Mojo, the payment provider collects and processes your payment details; we receive transaction status, order, amount, currency, and fulfilment records needed to complete and support the purchase.

3. How we use your information

  • Provide and operate the service (accounts, trips, sharing, expenses).
  • Read and parse booking emails and documents to build your itinerary.
  • Personalise destination ideas and nearby suggestions.
  • Send service communications (account confirmations, trip updates, security notices).
  • Improve, troubleshoot, secure, and prevent abuse of the service.
  • Comply with legal obligations.

We do not sell your personal information, and we do not use your data to train third-party AI models.

4. Connecting your Gmail

You can optionally connect a Gmail account so we can find your travel emails automatically. When you connect, Google asks you to grant the gmail.readonlyscope, which is read-only access to your Gmail. We use it for two things and nothing else: finding travel bookings (flights, hotels, car rentals, rail, activities) and extracting their details into your trips, and finding reward points statements so we can keep your points and miles balances current in Tripmojo. We don’t use it to read unrelated personal, financial, or medical email for any other purpose.

Which reward points statements. Reward points statements from airlines, hotel groups, other travel programmes and card issuers and banks are covered by connecting Gmail, and the connect screen lists them among the things we look for. You can turn reward points statements off at any time in Settings, under Consents, and we will stop. Turning them off does not disconnect Gmail or affect your booking confirmations.

In either case we read the points balance the statement states. We do not read, extract, infer or store your purchases, your transactions, your card spend, or your account balances in money.

What we access and store.Our servers query your mailbox for messages matching travel-booking searches and read those messages’ content, including HTML bodies and attachments (e.g. PDF confirmations), because that’s where booking details live. From them we store: the extracted booking details (dates, times, confirmation numbers, locations, prices), an archived copy of the source booking email and its attachments (so extraction can be re-run and so you can open the original), and scan bookkeeping (which message IDs we’ve already processed). Messages that don’t look like travel bookings are discarded after the automated check and are not stored.

Reward points statements.We search your mailbox for points statement emails (subject lines such as “points balance” or “miles summary”) and read the text of the messages that match. From a reward points statement we store: the programme, your balance and the unit it is counted in, the tier or status printed, the statement date, any expiry date the email states, and the membership number and member name as printed. We also keep a reference to the source message and a record of which messages we have already processed. We do not keep a copy of the statement email itself. For a card issuer programme we identify the account by the issuer and card name you confirm, never by a card number or its last four digits. Messages that turn out not to be reward points statements, including ordinary bank and credit card statements, are discarded after the automated check and are not stored.

Scanning runs on our servers, not on your device. We store the access we’re granted (an OAuth token) securely on our servers so we can perform the scans you ask for; we never place these tokens on your device. You can disconnect at any time in Settings → Connected accounts, or revoke access from your Google Account; deleting your Tripmojo account also revokes them and deletes the data described above.

Limited Use.Tripmojo’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we:

  • only use Gmail data to provide the user-facing features described here - importing your bookings, and keeping your loyalty balances current - never for advertising, market research, or building profiles unrelated to those features;
  • only transfer Gmail data to service providers acting as our processors for these features (Google’s Gemini API to extract booking and loyalty fields, and our Google Cloud hosting/storage - see Sections 5 and 6), as necessary to provide them, or when required by law;
  • do not sell Gmail data;
  • do not allow humans to read it, except with your explicit consent (e.g. a support request you initiate), for security or abuse investigations, or to comply with law;
  • do not use Gmail data to train generalised AI or machine-learning models.

5. AI features and automated processing

Tripmojo uses Google’s Gemini API to read your travel content and help organise it. Specifically, we send to Gemini:

  • the text and images of booking emails and documents you forward, upload, or that we find in a connected Gmail account, so it can extract booking details (dates, times, confirmation numbers, locations, and similar fields);
  • the text of travel loyalty statement emails found in a connected Gmail account, so it can extract your programme, balance, tier, membership number and statement date;
  • trip context and your profile/preferences, so it can suggest destinations, plans, and nearby activities.

Gemini processes this data under Google’s API terms and, per those terms, does not use it to train its models. AI output can be wrong or incomplete - always verify important details against the original source.

6. How we share information

We don’t sell your data. We share it only with service providers (“subprocessors”) that help us run Tripmojo and Airport Mojo, each processing data on our behalf under their own terms:

  • Google Cloud Platform - application hosting (Cloud Run, Cloud Scheduler), database (Cloud SQL), and file storage (Cloud Storage).
  • Vercel - web hosting and deployment.
  • Google Gemini API - AI processing of emails, documents, and trip context (Section 5).
  • Google APIs (Gmail, Maps/Places) - booking-email import (with your consent) and place/location lookups for suggestions.
  • Firebase (Google) - sign-in/authentication, push notifications (Cloud Messaging), analytics, and crash reporting (Section 7).
  • Cloudflare - inbound email routing and short-term storage of raw forwarded emails so we can process them.
  • Resend - sending transactional email (invites, confirmations, notices).
  • Google & Apple - when you choose to sign in with those providers.
  • Payment and fulfilment providers - payment processing and delivery when you choose to buy an eSIM or another paid product in Airport Mojo.

The third parties listed here process data on infrastructure primarily in the United States. We disclose information to law enforcement only when required by a valid legal request.

7. Analytics and crash reporting

We use Firebase (a Google service) for product analytics, performance monitoring, and crash reporting. Analytics records feature-usage events and screen views with an account identifier so we can understand and improve how the app is used. Crash reports include a one-way hashed account identifier plus diagnostic breadcrumbs (such as the screen you were on and connection state) - they do not include your emails, names, documents, or booking details.

8. Sharing within a trip

When you add someone to a trip as a Viewer, Editor, or Organiser, that person can see the trip’s contents (itinerary, bookings, members, expenses, comments, and activity history). If you add someone by email, we email them an invite and they gain access when they sign up. Public trips you share via a link are visible to anyone with the link.

We’re not responsible for how other trip members handle information you share with them. Only invite people you trust, and only add documents you’re comfortable sharing with that trip’s members.

9. Data retention and deletion

We keep your account and trip data for as long as your account is active. When you delete a trip, it and its attached files (bookings, itinerary, documents, comments, and expenses) are permanently deleted.

When you delete your account, we promptly delete your profile, preferences, connected-account tokens (and attempt to revoke them at the provider), notifications, push tokens, Wallet documents, and the trips you solely own; trips shared with other members continue under the remaining organiser. We also purge the raw copies of any emails you forwarded to us. Traveller reviews and their uploaded photos are deleted with the account; moderation and abuse records may be retained where necessary to protect the service and enforce our rules.

Deleted content may persist for a short time in our service providers’ encrypted backups before being overwritten on their normal backup cycles.

In Airport Mojo, deleting your account removes your profile, preferences, saved flight watches and alerts, notification tokens, reviews, uploaded review photos, and blocked- traveller list. Completed eSIM or other purchase records may be retained after being disconnected from your account where required for tax, accounting, fraud prevention, refunds, chargebacks, or legal compliance. See the dedicated Airport Mojo account and data deletion page for the exact steps.

10. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your data (you can delete your account in either app at any time, or follow the Airport Mojo deletion steps).
  • Export your data in a portable format.
  • Object to or restrict certain processing.

To exercise these rights, email us at contact@tripmojo.ai from the email address associated with your account.

11. Device permissions

With your consent, the app may ask for access to your camera and photo library (to scan and attach booking documents), your microphone and speech recognition (to dictate trip ideas in the planner), your approximate location (for nearby suggestions), and to send notifications. You can change or revoke any of these in your device settings at any time; the related features simply won’t work without them.

12. Children

Tripmojo and Airport Mojo are not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

13. International transfers

Our infrastructure is hosted in the United States. If you use either app from outside the U.S., your information will be transferred to and processed in the U.S.

14. Security

We use industry-standard measures to protect your information, including encrypted transport (TLS), encrypted storage at rest, and server-side authorization checks on every data access (clients never talk to the database directly). Gmail OAuth tokens are stored only on our servers, never on your device. No system is perfectly secure, but we take our obligations seriously.

15. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced in-product or by email. The “Last updated” date at the top of this page reflects the most recent revision.

16. Contact

Privacy questions, data requests, or anything else: contact@tripmojo.ai.

Your next trip is one email away

Solo getaway, family holiday or group trip - 100% free, no paywall, no subscription.