Privacy Policy
Last updated: 17 September 2026
Sunnoro ("we", "us") is an app that plans trips for families and couples. It is operated by Sunnoro, which is the data controller for the personal data described here.
Short version: we collect only what we need to plan your trips. We don't sell your data, we don't show third-party ads, and you can delete everything at any time.
1. Data we collect
| Data | Examples | Why | Legal basis (GDPR) |
|---|---|---|---|
| Travel profile ("Travel DNA") | Home city, who travels (number of adults, children's ages and optional first names), pace, budget, interests, dietary needs, mobility needs (e.g. stroller, wheelchair), nap and bedtime times, driving preference, free-text notes | To personalise trip plans | Contract (providing the service). Dietary and mobility details are only used with your explicit consent, which you give by entering them. |
| Trips | Destination, dates, accommodation name/address, arrival and departure details, must-dos, generated itineraries, items you mark as done | To create, store and sync your plans | Contract |
| Booking documents you import | Screenshot or PDF of a booking confirmation | To extract dates, place and times. The file is processed once and not stored on our servers. | Contract |
| Concierge questions | Questions you ask about your trip | To answer them | Contract |
| Account data | A random user ID. If you sign in: email address and sign-in provider (Apple, Google or email). With Sign in with Apple you can hide your email. | To keep your trips across devices and restore purchases | Contract |
| Purchase status | Whether you have Plus or a Trip Pass, and transaction IDs. We never see your card details; Apple or Google processes payments. | To unlock paid features | Contract |
| Technical and usage data | Device install ID, app version, IP address (transiently), request logs, number of trips generated per month | Security, abuse prevention, fair-use limits, debugging | Legitimate interests |
We do not collect your precise location, contacts, photos (other than a file you choose to import), or advertising identifiers, and we don't track you across other apps or websites.
2. How AI is used
To create your plan, we send the relevant parts of your travel profile and trip details to our AI providers through their paid, commercial APIs: Google (Gemini API, including Grounding with Google Maps to find real, currently operating places) and Anthropic (Claude), which we use as a backup. Under these paid API terms, your inputs and outputs are not used to train their models and are kept only for a limited period for abuse monitoring. We don't send your name, email or account ID to the AI providers. Places we recommend from Google Maps are shown with a "Google Maps" source link.
AI-generated plans can contain mistakes. See our Terms.
3. Who processes your data
| Provider | Purpose | Location |
|---|---|---|
| Google LLC (Gemini API, Google Maps) | AI trip planning, place data | USA |
| Anthropic, PBC | AI trip planning (backup) | USA |
| Supabase, Inc. | Account authentication and database hosting (trips, profile, usage counters) | EU (Ireland) |
| Sendinblue SAS (Brevo) | Sending sign-in code emails | EU (France) |
| Cloudflare, Inc. | API hosting, website hosting, security | Global edge network |
| RevenueCat, Inc. | In-app purchase validation and subscription status | USA |
| Apple / Google | App distribution, payments, Sign in with Apple / Google | Global |
| MET Norway | Weather forecasts (only destination coordinates are sent) | Norway |
| Expo (650 Industries) | App updates delivery | USA |
Where data is transferred outside the EEA/UK, we rely on the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework, as applicable.
4. We don't sell your data
We never sell or rent personal data, and we don't share it for cross-context behavioural advertising.
5. Affiliate links
Some buttons (for example "Find hotels", "Book tickets", "Compare rental cars", "Get an eSIM", "Travel insurance") open partner websites such as Booking.com, GetYourGuide, DiscoverCars, Airalo or SafetyWing. If you book, we may earn a commission at no extra cost to you. These links contain our partner ID and the search you asked for (for example destination and dates), but no personal data about you. Once you're on the partner's site, their privacy policy applies. Partners cannot pay to be included in your itinerary.
6. Children
Sunnoro is intended for adults (18+) planning trips. Parents may enter their children's ages and, optionally, first names so plans suit the family. Please enter only what's useful: ages are enough. We don't knowingly collect data directly from children. If you think a child has given us personal data, contact us and we'll delete it.
7. Retention
- Profile, trips and account data: kept until you delete them or your account.
- Anonymous accounts that have been inactive for 18 months are deleted automatically.
- Imported booking files: not stored. They are processed in memory and discarded.
- Server logs: up to 30 days.
- Purchase records: as long as required by tax and accounting law.
8. Your rights
Depending on where you live (for example under GDPR, UK GDPR or CCPA/CPRA), you can: access your data, correct it, delete it, export it, restrict or object to processing, and withdraw consent at any time. You can also complain to your local data protection authority.
Most of this is built into the app: edit your Travel DNA under You → Travel DNA, delete trips from the trip screen, and delete your account under You → Delete account. For anything else, email privacy@sunnoro.com. We reply within 30 days.
9. Security
All data is encrypted in transit (TLS). Database access is protected by row-level security so each user can only access their own data. AI and payment keys stay on our servers and are never shipped in the app.
10. Changes
If we make material changes, we'll tell you in the app before they take effect.
11. Contact
Sunnoro
Email: privacy@sunnoro.com