Privacy Policy
Porvi ("Porvi", "we", "us") is an AI travel planning app operated by Dmitrii Okunev, an individual developer based in Spain. This policy explains what personal data Porvi collects, how it is used, and the choices you have. For any privacy question or request, contact okdiman@proton.me.
1. Information we collect
Account information. Sign-in is handled by Supabase. When you create an account — with email or via Google or Apple — we receive and store your user ID, email address, and, if provided by the sign-in provider, your name and profile picture URL. We never receive or store your password; Google and Apple sign-in is performed entirely on their side.
Travel preferences ("Travel DNA"). The travel style, pace, budget level, and interests you select during onboarding or edit in your profile.
Trip requests and itineraries. The destination, travel dates, and preferences you submit when generating a trip, and the itineraries generated for you, including changes you make to them (rebuilding a day, replacing a stop).
Shared itineraries. If you share an itinerary, we create a share link for it. Anyone who opens that link while signed in to Porvi can preview the itinerary and add it to their trips, where it appears read-only and labelled with your name as the person who shared it. What they get is not a copy but continued access to your itinerary: if you later change it, they see the change. Share links are unguessable, but they are not otherwise restricted — anyone who receives the link can use it, so share it only with people you intend to. There is currently no way to un-share an itinerary; to withdraw access you have to delete the itinerary, which removes it for everyone it was shared with. Deleting your account has the same effect on everything you shared.
Technical data. Our servers process your IP address for rate limiting and abuse prevention, and keep standard request logs (endpoint, status code, timing). Request logs do not include the content of your requests in production.
Purchases. If you buy a subscription, payment is processed entirely by Apple (App Store) or Google (Google Play) — we never receive your payment card details. We receive the purchase confirmation and your subscription status, managed for us by RevenueCat under a pseudonymous app user ID, so the app can unlock paid features.
Usage analytics. We use PostHog and Google Firebase Analytics to collect app usage events (such as screens opened and features used) together with device model, operating system, app version, and language. The same events go to both, so that we can cross-check them. Before you sign in, these events are tied to a random identifier generated on your device; after you sign in, they are tied to your Porvi user ID, which means analytics data is linked to your account. We do not send your email address, name, or the content of your itineraries to either analytics provider. Analytics data is not used for advertising, is not shared with ad networks, and Porvi does not track you across other companies' apps or websites.
Crash diagnostics. We use Google Firebase Crashlytics to find out when the app crashes. If a crash happens, Crashlytics sends us a technical report: where in the code the crash occurred, the device model, operating system and app version, the state of the device at that moment (such as free memory), and an identifier Crashlytics generates for the app installation. Crash reports do not contain your itineraries or your account details.
We do not collect your precise device location. Places in your itineraries come from the destination you type, not from GPS.
2. Use without an account
You can generate a trip without signing in. In that case no account data is collected; the generated itinerary is stored so the app can display and resume it, and is automatically deleted from our servers within about 30 days.
3. How we use your data
- To generate and personalize travel itineraries — the core function of the app.
- To store your trips so you can view, resume, and edit them.
- To let you share an itinerary with other people, and to let you accept one shared with you.
- To process purchases and manage your subscription.
- To understand how the app is used and improve it (product analytics).
- To detect and fix crashes and other technical failures (crash diagnostics).
- To operate, secure, and debug the service (rate limiting, abuse prevention, logs).
We do not sell your personal data, do not share it for advertising, and do not use it for profiling beyond the travel personalization you explicitly set up.
4. AI processing
Itineraries are generated using Claude, an AI model provided by Anthropic. To generate a trip, we send Anthropic the information needed for the task: your destination, dates, travel preferences, and the itinerary being edited. We do not send your email address or account identifiers. Under Anthropic's commercial API terms, data submitted via the API is not used to train Anthropic's models.
5. Service providers
Porvi relies on the following providers to operate. Each receives only what is necessary for its function:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Authentication | Email, sign-in identity (Google/Apple), name, profile picture |
| Anthropic | AI itinerary generation | Destination, dates, travel preferences, itinerary content |
| Railway | Server and database hosting | All data listed in this policy (as our infrastructure host) |
| Google (Places, Routes) | Place search, details, transit times | Place names and identifiers from your itinerary; no account data |
| Mapbox | Walking/driving directions, place photos | Place coordinates and identifiers; no account data |
| Foursquare, Wikimedia (Wikidata) | Place photos | Place names and identifiers; no account data |
| Cloudflare (R2) | Storage of place photos | Photos of public places only; no user data |
| RevenueCat | Subscription management | Purchase receipts, subscription status, pseudonymous app user ID; no card details |
| PostHog | Product analytics | Usage events, device model, OS and app version, language; device-generated identifier before sign-in, Porvi user ID after |
| Google (Firebase Analytics) | Product analytics (second copy of the same events) | Same as PostHog |
| Google (Firebase Crashlytics) | Crash reporting | Crash stack traces, device model, OS and app version, device state, installation identifier |
6. Data retention
- Account, preferences, and saved trips — kept while your account exists, deleted when your account is deleted.
- Itineraries created without an account — deleted automatically within about 30 days.
- Server logs — kept for a short period for security and debugging, then discarded.
- Analytics data — retained only as long as needed for product analytics and deleted on account-deletion requests.
- Crash reports — retained by Firebase Crashlytics for a limited period (currently about 90 days) and then deleted automatically.
- Itineraries shared with you — we keep the fact that they were shared with you for as long as both accounts and the itinerary exist. The itinerary itself belongs to the person who shared it: if they delete it or delete their account, it disappears from your trips too.
- Cached place data (photos, opening hours, routes between places) describes public places, not you, and is not linked to your identity.
7. Your rights and choices
- You can view and edit your profile and travel preferences in the app.
- You can delete any saved trip in the app; deletion is immediate and permanent.
- You can delete your account, together with all associated data (profile, travel preferences, saved trips), directly in the app. You can also request deletion — or a copy of your data — by emailing okdiman@proton.me; we respond within 30 days.
- Depending on where you live (e.g. the EU/EEA or UK under the GDPR, or California under the CCPA), you may have additional rights — access, correction, deletion, portability, and objection. Requests for any of these go to the same address. If you are in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority (in Spain, the AEPD).
8. Security
All traffic between the app and our servers is encrypted with TLS. Access to production data is restricted, and API keys for the services above are held only on our servers — the mobile app never talks to the AI provider directly.
9. Children
Porvi is not directed at children under 13 (or the higher minimum age required in your country), and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.
10. Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected by updating the effective date at the top of this page, and where feasible we will notify you in the app.
11. Contact
Questions, concerns, or requests: okdiman@proton.me.