Privacy Policy
Effective: September 3, 2026 · Last updated: September 3, 2026
This policy describes what Zups collects, how we use it, who we share it with, and the choices you have. If something changes materially, we will update this page and update the "Last updated" date above.
Zups is operated by James Zupa ("Zups", "we", "us"). Questions about this policy can go to jameszupa@zupstravel.com.
Summary
- Zups is a travel planning app. We collect the information needed to run it — nothing more.
- Zups does not collect your precise device location (GPS). Zups uses a home city and airport that you choose from a list, not your phone's location.
- Zups does not ship third-party advertising SDKs, does not display third-party behavioral advertisements in the app, and does not use third-party analytics vendors, crash reporters, or session replay tools.
- You can create an account using Sign in with Apple, Google, or email (with a password or a one-time email link). When you use Apple or Google, we receive only what those providers share with us.
- Every Zups account is private by default. Your postcards and profile are not visible to other Zups users on any public feed or search surface.
- You can delete your account at any time from Settings → Danger Zone → Delete Account. Deletion removes your account and account-associated content, subject to the specific retained records described below.
1. Information we collect
Before you create an account
When you first open the app to go through onboarding, Zups creates a temporary anonymous session on our backend so your onboarding choices (for example, your typed home city and travel preferences) can persist before you register. If you complete signup, that anonymous session is upgraded into your registered account and the onboarding choices become part of it.
Account and profile information
- Sign-in identifier from your chosen sign-in method:
- Sign in with Apple: an Apple-issued identifier and, if you allow it, the email Apple provides (which may be Apple's private-relay address). On your first sign-in only, Apple may also share your name.
- Continue with Google: a Google-issued identifier and the email associated with your Google account.
- Email: the email address you provide, plus a password (if you chose password sign-in) or a one-time email link (if you chose the email-link option).
- Profile details you enter in the app: username, bio, profile photo, home city, home airport (a 3-letter airport code you choose from a list), number of travelers, and passport country (optional).
Content you create
- Trips you plan (destinations, dates, saved templates, notes).
- Postcards you create (photo you upload, caption, back-of-postcard text, template selection).
- Journal entries you write inside the app.
- Saved trips, saved trip collections, and any community memberships you join.
Photos and media
If you upload a photo (for your profile or a postcard), the photo is stored on Zups' backend infrastructure so we can display it back to you and, if you share the postcard into a Community you have joined, to other members of that Community. Zups does not send your uploaded photos to advertising networks or booking partners.
Home base — no GPS
Zups needs to know your "home airport" to plan trips from it. You choose this manually — you type a city name, Zups looks it up against OpenStreetMap's public geocoder to find the nearest airports, and you pick one. Zups stores the city name and 3-letter airport code. Zups does not store latitude/longitude, and Zups does not ask your device for your GPS location. The iOS Location permission dialog does not appear in the app.
How you use the app (product analytics)
Zups records first-party product-interaction events — for example, opening a trip idea, saving a trip, starting to plan, or tapping a booking link. This helps us understand which content is useful and which is not. These events are stored in Zups' own backend, linked to your account. Zups does not send them to Amplitude, Mixpanel, PostHog, Google Analytics, Segment, Facebook, or any other third-party analytics vendor. There is no third-party analytics SDK in the app.
Booking handoff records
When you tap a "book with" link inside Zups, we log the fact that you clicked it — including origin, destination, and dates — so we can understand what people are trying to book. If a partner completes a booking, they may send us a delayed confirmation (see "Booking partners" below). No credit card, passport, or personal booking detail is ever sent through Zups — you complete the booking on the partner's website.
Support communications
If you email us, we keep the email so we can respond.
What Zups does not collect
- Precise device location (GPS).
- Contacts, calendar, microphone, or camera roll access (beyond a photo you deliberately select for upload).
- Advertising identifiers.
- Cross-app tracking data.
- Health, financial, or biometric information.
2. How we use your information
- To run the app: display your trips, postcards, journal, and profile back to you.
- To sign you in and keep your session active.
- To send booking-partner links pre-filled with your trip context (origin, destination, dates) so the partner's search page opens with the right query.
- To understand which product features are useful, in aggregate, from your first-party interaction events.
- To respond to your support requests.
- To comply with law when we're legally required to.
We do not use your information for advertising, retargeting, profiling, or sale to data brokers.
3. Location — clear statement
Zups does not obtain your precise location from your device. The iOS Location permission prompt does not appear in the Zups app. The only "location" data associated with your account is the home city label and 3-letter airport code you chose during onboarding. You can change this in Settings at any time.
4. Who we share information with
Zups uses a small number of trusted service providers to operate. Each receives only what they need to do their job.
| Provider | What they do for Zups | What they receive |
|---|---|---|
| Supabase | Database, authentication, storage, edge functions (our primary backend) | Everything you save in Zups: account, profile, trips, postcards, journal, product events. |
| Apple | Sign in with Apple | Apple's own identifier for you. If you use Apple's private-relay email, we receive the relay address, not your real email. |
| Continue with Google (OAuth) | Google's own identifier for you and the email associated with your Google account. | |
| Expo (EAS) | Mobile app builds and over-the-air updates | App bundles and update channels — no user data. |
| OpenStreetMap Nominatim | Converts a city name you type into approximate coordinates so we can suggest nearby airports | The city string you typed and a generic "ZupsApp" User-Agent. No account identifier. |
| Google Routes API | Ground transit routing between cities you've added to a trip | Origin and destination city references. No account identifier. Query is made from our servers, not your device. |
| Compensated affiliate providers (Kiwi.com via Travelpayouts, Expedia) | Provide flights and accommodations you can book. Zups may earn a commission on qualifying bookings, at no extra cost to you. Zups is not the seller. | The trip parameters needed to pre-fill the provider's search — origin, destination, dates, number of adults — plus Zups' affiliate marker. See Affiliate Disclosure. |
| Other external providers (Hostelworld, Rome2Rio, GetYourGuide, Viator, and individual ferry operators for certain island routes) | Provide additional accommodations, ground transport, routing information, and experiences you can plan or book. Zups is not the seller and does not currently earn a commission from these links. | The trip parameters needed to pre-fill the provider's search — origin, destination, dates, number of adults. |
| fal.ai (server-side only) | Generates editorial images used inside the app | Text prompts written by us — no user data. |
We do not share your information with advertisers, data brokers, marketing platforms, or any party not listed above.
Booking partner data — what actually gets sent
When you tap a "book flights", "find hotels", "browse experiences" or similar link, Zups opens the partner's website with a URL that includes: the trip context (origin, destination, dates, adult count) and our affiliate marker. Zups also includes a random identifier used solely so the partner can tell us if a booking eventually completes. This random identifier is not your Zups account ID or email — it's a separate opaque token stored server-side. We do not send your name, email, Apple identifier, or precise location to booking partners.
Once you land on the partner's website, the partner's own privacy policy governs what happens next — including any cookies they set, any account you create with them, and any booking you make.
5. Sign-in methods
You can create or sign into a Zups account using any of the following:
- Sign in with Apple. Apple gives us an opaque identifier for you, an email address (which may be Apple's private-relay address), and — on your first sign-in only — your name if you chose to share it. If you use Apple's "Hide My Email" relay, we cannot see your real email address.
- Continue with Google. Google gives us an opaque identifier for you and the email address associated with your Google account.
- Email. You can create a Zups account using an email address and a password, or by requesting a one-time email link that signs you in.
When you delete your Zups account (see below), and if you originally signed in with Apple, Zups attempts to revoke Apple's authorization so the link between your Apple ID and the deleted Zups account is severed. If you later sign into Zups with the same Apple ID, Apple treats it as a brand-new user and you get a fresh, empty account.
6. Postcard and profile visibility
Every Zups account is private by default. This is enforced by Zups' backend access rules, not just by the app's user interface:
- Your postcards, saved trips, journal entries, and follows are visible only to you.
- Other users cannot search for you, view your profile, or see your postcards.
- Communities (topic groups seeded by Zups — for example, Solo Travelers, Europe, Budget Travel) are the one shared surface in the app. If you post a postcard to a Community you have joined, other members of that Community can see it. Community postcards are served through signed, time-limited URLs and are not publicly indexable.
- The Zups app does not currently offer a control to make your account public. If that changes in a future release, this page will be updated before that change takes effect.
7. User-generated content, reporting, and moderation
You control the content you create. Zups supports reporting and blocking so other members of a Community can flag content they find objectionable:
- Any user can report a postcard shared to a Community. Reports go into our system for review.
- If three or more distinct users report the same postcard, it is automatically hidden from public view pending review.
- Users can also block other users; blocked users cannot interact with your content.
- We also apply a server-side content filter that rejects obviously abusive text in postcards before it ever becomes visible.
- We review reports and respond to launch-blocking abuse within a reasonable time. For urgent safety concerns, email jameszupa@zupstravel.com.
8. Deleting your account
You can delete your Zups account from inside the app:
Settings → Danger Zone → Delete Account → confirm twice.
When you delete your account, Zups:
- Deletes your account and your profile.
- Deletes your account-associated content, including the trips you planned, the postcards you created, your journal entries, saved trips, follows, community memberships, blocks, and reports.
- Deletes the files you uploaded to Zups — profile photo, postcard photos, and any trip images or videos.
- If you originally signed in with Apple, attempts to revoke Apple's authorization so Sign in with Apple later creates a fresh account instead of resurrecting the old one.
What is retained after deletion, and why: Zups keeps aggregate booking-handoff and booking-link-click records — rows that log which trip context led to which partner click. Before these records are retained, your account identifier is removed from them, so they are no longer associated with your Zups account. Zups keeps them to understand which trip ideas convert into booking attempts, in aggregate, and for partner attribution. These records are retained in a form no longer associated with your Zups account, and they still contain the trip-context fields already in the row (origin, destination, dates, partner).
Authentication server logs held by our infrastructure providers (records that a login happened, tokens issued, etc.) are retained by those providers under their own retention policies and are not directly controllable by Zups.
If you'd rather delete your account by email — for example if you can't get into the app — write to jameszupa@zupstravel.com from the email associated with your account (or from your Apple-relay email) and we will process it manually.
9. Data retention
We keep your account data for as long as your account exists. If you delete your account, we delete it as described above. If you become inactive but don't delete your account, we keep your data so it's ready when you come back.
Support emails are kept for as long as needed to help you, then discarded.
10. Data location
Zups' primary backend (Supabase) currently runs in the United States. If you use Zups from outside the US, you're consenting to your data being processed there. Apple, Expo, and our booking partners operate globally.
11. Minimum age
Zups is not intended for anyone under the age of 16, and we do not knowingly collect data from anyone under 16. If you believe someone under 16 has created a Zups account, email us and we will delete it.
12. Your choices and rights
- Edit your profile at any time in Settings.
- Delete your account at any time in Settings.
- Ask us what we hold about you, by emailing jameszupa@zupstravel.com.
- Ask us to correct or delete something specific.
- If you're in the EU/UK, you have GDPR rights (access, correction, erasure, portability, objection); if you're in California, you have CCPA/CPRA rights (know, delete, correct, opt out of "sale/sharing"). Concretely: Zups does not ship any third-party advertising SDK, does not display third-party behavioral advertisements in the app, and does not sell personal information for money. Booking-handoff URLs transmit the trip parameters described in Section 4 to the partner you chose; those parameters are then processed by the partner under the partner's own terms and privacy policy.
See Manage Your Data for the practical how-to.
13. Security
We use standard industry practices: TLS for data in transit, database access controls on the Zups backend, and industry-standard authentication (Sign in with Apple, Google OAuth, or email with password or one-time link). No system is perfectly secure. If you find something concerning, email jameszupa@zupstravel.com.
14. Changes to this policy
If we change this policy materially, we'll update the "Last updated" date at the top and, for meaningful changes, notify active users inside the app or by email.
15. Contact
Get in touch
Zups
Email: jameszupa@zupstravel.com
For account deletion, privacy questions, or data requests, please use the email above.