Back to Mapliva

The short version

Your photo files stay on your phone during trip detection. A first pass that notices whether you travelled at all runs entirely on your iPhone. If you then use the AI photo flow, Mapliva sends structured photo evidence — including timestamps, GPS coordinates, photo counts, and related travel clues — through our Firebase backend to OpenAI so it can group possible trips. This can happen before you approve a suggested trip. Candidate evidence and local photo identifiers can also sync to your private Firebase account. Approved trips, goals, and stamps sync so they survive a new phone. Share cards and flyover videos are composed on your device. We also use Firebase for product-usage analytics, crash reports, performance monitoring, and a simple daily record that the app was opened, as described below. If Mapliva's paid edition, Voyager, becomes available and you subscribe, we process Apple's purchase identifiers so the right account gets access — we never see your card details. Nothing is used to train a model. We share only with the named service providers below, and only as needed to run the app.

This website (the marketing pages and the in-browser Stamp Game) uses Google Analytics 4 with analytics storage denied by default. If you accept website analytics, GA4 can set cookies to count visits, understand which pages and main buttons people use, and measure aggregate Stamp Game progress and sharing actions. We do not send your exact city selections to GA4. You can decline or change your choice at any time.

If anything in this policy is unclear, write to team@otrip.app and a human will reply.

Who we are

Mapliva ("Mapliva", "we", "our") is a personal travel journal for iPhone. For the purposes of the EU and UK General Data Protection Regulation, the Mapliva team is the data controller of the personal data processed through the app and this website (together, the "Service"). Contact details are at the bottom of this page.

What Mapliva accesses on your device

Mapliva works inside the iOS sandbox, which means we can only see what you explicitly grant through system permissions or what you type into the app. Specifically:

Information we collect

Account information

Travel content you create

Subscription and purchase information

Account activity

Device and usage information

Diagnostics

How we use information

We use the information described above to:

Under the GDPR, the legal bases we rely on are contract (to provide the Service you asked for, including handling a subscription you bought), consent (for optional features such as Photos access or Location History import — withdrawable at any time), legitimate interest (to keep the Service stable, secure, and abuse-free, balanced against your interests), and legal obligation where the law requires us to process certain data.

Website analytics (this site only)

The pages on mapliva.app — the marketing site, the in-browser Stamp Game demo, and these legal pages — load Google Analytics 4 (GA4) with analytics storage denied by default. Before you accept, GA4 cannot set or read analytics cookies; Google's advanced consent mode may still receive a cookieless ping containing consent state and basic page measurement. If you accept, we use GA4 to see visit counts, which pages are read, which main site buttons are used, aggregate Stamp Game stages and counts, sharing methods, and roughly where in the world traffic comes from. This website measurement is separate from the native Firebase Analytics events collected by the Mapliva iPhone app and described under “Device and usage information” above.

After you accept, what GA4 receives: the page URL you visited, page title, your referrer (the previous page or search engine), device type and screen size, browser language, an IP-derived approximate location (city / region level, with the full IP discarded), main-button event details, and Stamp Game events such as whether play started, aggregate numbers of stamps/countries/continents, results tabs viewed, restart, and sharing method. We do not send the particular cities or countries you selected. GA4 also receives a randomly-generated cookie identifier so a return visit can be counted as the same browser. What it does not receive: your name, email, account information, photos, exact Stamp Game selections, trip data, or anything you've entered into the app.

If you accept, GA4 can set first-party cookies named _ga and _ga_DNLYM84X3S on this site. They expire after 2 years. We rely on your consent for cookie-based website analytics. If you decline, analytics storage stays denied and Mapliva does not send custom main-button events. You can:

Sharing a Stamp Game atlas. Playing the game keeps your city selections in your browser. If you choose to share your atlas — the share link, or the poster shared with its link — those city selections travel inside the link (for example mapliva.app/a?s=par,tyo), because anyone opening it has to be able to see the same atlas. Opening such a link asks our Firebase backend to draw the preview card for it, so the city list appears in our server request logs, which we keep for up to 30 days. Nothing else about you is attached, and a game you never share is never sent to us.

We do not run advertising on this website, we do not use GA's advertising or remarketing features, and we have not enabled Google Signals (cross-device tracking via signed-in Google accounts).

AI features and what we send to OpenAI

Mapliva uses AI to help draft trips from your photos, run the assistant, and compose year-in-review summaries. These features call OpenAI through a backend we host on Firebase Cloud Functions.

What is sent to OpenAI: when you start the AI photo flow, Mapliva can send structured evidence before you approve a suggested trip. That evidence can include photo timestamps, GPS coordinates, grouped photo counts and durations, airport hints, and optional home-city or home-airport references. Other AI features can send dates, destination labels, airport and country codes, and text you submit to the assistant or trip-building flow. What is not sent to OpenAI: photo image or video files, local PhotoKit identifiers, sign-in credentials, or push tokens.

We use OpenAI's API with the default setting that prompts and outputs are not used to train OpenAI's models. OpenAI may retain inputs and outputs for up to 30 days for abuse and safety monitoring, after which they are deleted, in line with their API data-handling commitments.

AI suggestions are probabilistic. They can be incomplete or wrong. You decide what is saved to your travel record. You can avoid AI features entirely by using the manual entry flow (Type it in) instead of the photo-flow or assistant.

Service providers we share data with

We do not sell your personal information and we do not share it for cross-context behavioural advertising. We share data with the providers below ("subprocessors") only as needed to operate the Service. Each acts under a written agreement that restricts how they may use your data and requires them to apply appropriate security measures.

We may add or change subprocessors as the Service evolves. When we do, we'll update this list and, for material additions, surface a notice in the app or this page before the change takes effect.

Beyond subprocessors, we may also disclose information when required by law, to enforce our Terms, to protect the rights, property, or safety of Mapliva, our users, or others, or in connection with a merger, acquisition, or sale of assets (in which case we will use reasonable efforts to notify you in advance).

International data transfers

Mapliva is built on cloud infrastructure that may store and process your data in countries other than your own, including the United States. Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that is not the subject of an adequacy decision, we rely on the Standard Contractual Clauses approved by the European Commission and, where applicable, the UK International Data Transfer Addendum, together with supplementary measures (encryption in transit and at rest, scoped access controls, audit logging).

You can request a copy of the safeguards in place by writing to team@otrip.app.

Retention and deletion

We keep your information for as long as your account is active and only as long as we need it.

Security

We use technical and organisational measures designed to protect your data, including TLS encryption in transit, encryption at rest in Firebase's managed services, Firestore security rules that enforce per-user authorisation on every read and write, scoped service-account access, audit logging, and least-privilege principles for internal access. Authentication is handled by Firebase Authentication; we do not store passwords for email sign-in ourselves.

No system is perfectly secure. If we become aware of a security incident that affects your personal data, we will notify you and the appropriate regulators where required by law.

Your privacy rights

Subject to local law, you have the following rights in relation to your personal data, and many of them you can exercise directly in the app:

If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) gives you the right to know what personal information we have collected, the right to delete it, the right to correct it, the right to opt out of the sale or sharing of personal information (we do neither), the right to limit use of sensitive personal information, and the right not to be discriminated against for exercising these rights. Residents of Colorado, Connecticut, Virginia, Utah, and other US states with comparable laws have similar rights and may exercise them through the same contact channel.

To exercise any of these rights, write to team@otrip.app. We may need to verify your identity before responding and will reply within the timeframe required by applicable law (one month under GDPR, extendable by two further months for complex requests).

Children

Mapliva is not directed to children under 13, or the equivalent minimum digital-consent age in your jurisdiction (for example, 16 in parts of the EEA, 14 in some EU member states). We do not knowingly collect personal information from children below that age. If you believe a child has provided us with personal information without parental consent, please write to us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to our practices, the Service, or applicable law. When we make material changes we will surface a notice inside the app and update the "Effective" date at the top of this page before the changes take effect. Continued use of the Service after that date means you accept the updated policy.

Contact

For privacy questions, subprocessor inquiries, or data-subject requests, write to team@otrip.app. For general questions, the in-app support channel is also fine.

If you are located in the EEA, the UK, or Switzerland, you have the right to lodge a complaint with your local supervisory authority.