Privacy Policy

Last updated: 17 September 2026

Sunnoro ("we", "us") is an app that plans trips for families and couples. It is operated by Sunnoro, which is the data controller for the personal data described here.

Short version: we collect only what we need to plan your trips. We don't sell your data, we don't show third-party ads, and you can delete everything at any time.

1. Data we collect

DataExamplesWhyLegal basis (GDPR)
Travel profile ("Travel DNA")Home city, who travels (number of adults, children's ages and optional first names), pace, budget, interests, dietary needs, mobility needs (e.g. stroller, wheelchair), nap and bedtime times, driving preference, free-text notesTo personalise trip plansContract (providing the service). Dietary and mobility details are only used with your explicit consent, which you give by entering them.
TripsDestination, dates, accommodation name/address, arrival and departure details, must-dos, generated itineraries, items you mark as doneTo create, store and sync your plansContract
Booking documents you importScreenshot or PDF of a booking confirmationTo extract dates, place and times. The file is processed once and not stored on our servers.Contract
Concierge questionsQuestions you ask about your tripTo answer themContract
Account dataA random user ID. If you sign in: email address and sign-in provider (Apple, Google or email). With Sign in with Apple you can hide your email.To keep your trips across devices and restore purchasesContract
Purchase statusWhether you have Plus or a Trip Pass, and transaction IDs. We never see your card details; Apple or Google processes payments.To unlock paid featuresContract
Technical and usage dataDevice install ID, app version, IP address (transiently), request logs, number of trips generated per monthSecurity, abuse prevention, fair-use limits, debuggingLegitimate interests

We do not collect your precise location, contacts, photos (other than a file you choose to import), or advertising identifiers, and we don't track you across other apps or websites.

2. How AI is used

To create your plan, we send the relevant parts of your travel profile and trip details to our AI providers through their paid, commercial APIs: Google (Gemini API, including Grounding with Google Maps to find real, currently operating places) and Anthropic (Claude), which we use as a backup. Under these paid API terms, your inputs and outputs are not used to train their models and are kept only for a limited period for abuse monitoring. We don't send your name, email or account ID to the AI providers. Places we recommend from Google Maps are shown with a "Google Maps" source link.

AI-generated plans can contain mistakes. See our Terms.

3. Who processes your data

ProviderPurposeLocation
Google LLC (Gemini API, Google Maps)AI trip planning, place dataUSA
Anthropic, PBCAI trip planning (backup)USA
Supabase, Inc.Account authentication and database hosting (trips, profile, usage counters)EU (Ireland)
Sendinblue SAS (Brevo)Sending sign-in code emailsEU (France)
Cloudflare, Inc.API hosting, website hosting, securityGlobal edge network
RevenueCat, Inc.In-app purchase validation and subscription statusUSA
Apple / GoogleApp distribution, payments, Sign in with Apple / GoogleGlobal
MET NorwayWeather forecasts (only destination coordinates are sent)Norway
Expo (650 Industries)App updates deliveryUSA

Where data is transferred outside the EEA/UK, we rely on the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework, as applicable.

4. We don't sell your data

We never sell or rent personal data, and we don't share it for cross-context behavioural advertising.

5. Affiliate links

Some buttons (for example "Find hotels", "Book tickets", "Compare rental cars", "Get an eSIM", "Travel insurance") open partner websites such as Booking.com, GetYourGuide, DiscoverCars, Airalo or SafetyWing. If you book, we may earn a commission at no extra cost to you. These links contain our partner ID and the search you asked for (for example destination and dates), but no personal data about you. Once you're on the partner's site, their privacy policy applies. Partners cannot pay to be included in your itinerary.

6. Children

Sunnoro is intended for adults (18+) planning trips. Parents may enter their children's ages and, optionally, first names so plans suit the family. Please enter only what's useful: ages are enough. We don't knowingly collect data directly from children. If you think a child has given us personal data, contact us and we'll delete it.

7. Retention

8. Your rights

Depending on where you live (for example under GDPR, UK GDPR or CCPA/CPRA), you can: access your data, correct it, delete it, export it, restrict or object to processing, and withdraw consent at any time. You can also complain to your local data protection authority.

Most of this is built into the app: edit your Travel DNA under You → Travel DNA, delete trips from the trip screen, and delete your account under You → Delete account. For anything else, email privacy@sunnoro.com. We reply within 30 days.

9. Security

All data is encrypted in transit (TLS). Database access is protected by row-level security so each user can only access their own data. AI and payment keys stay on our servers and are never shipped in the app.

10. Changes

If we make material changes, we'll tell you in the app before they take effect.

11. Contact

Sunnoro
Email: privacy@sunnoro.com