Privacy Policy

Last updated June 29, 2026

liuliu (“we,” “us,” or the “app”) is a travel app for planning trips and reliving them on a 3D globe. This policy explains what we collect, why, and what choices you have. The short version: your trips are yours, we collect only what the app needs to work, and we don’t sell your data.

Information we collect

We collect the following, and nothing more:

  • Account information. When you sign in, our authentication provider (Clerk) handles your credentials, including your email address or social-login identity and your name. Our own servers never store these — we only ever receive and store an opaque account identifier that links your trips to you. We never see or store your password.
  • Trip content you create. The trips and events you add are stored on our servers so they sync to your device, and a copy is kept on your device so you can view and edit your trips offline — your offline changes sync back to our servers the next time you’re online. This includes trip titles and dates, the currency and any cost amounts you enter to budget a trip, and for each event: place names, map coordinates (latitude and longitude), city names, travel and lodging details, hotel names, and any free-text notes you write. Because trips are made of places, this content includes location information that you choose to enter.
  • Documents you attach. If you attach a document to a trip or an event — for example a PDF or an image of a boarding pass, ticket, hotel voucher, visa, or insurance — the file is stored on our servers so you can view it later and it stays with your trip. We store the file itself and basic details about it (its name, type, size, and when you added it). We only store documents you deliberately attach; we don’t access your photos or files otherwise. Documents are available only while you have a connection — they aren’t downloaded for offline viewing.
  • Search text you type. When you search for a place to add to a trip, or for a cover photo, the text you type is sent as you type it to return matching results: place searches go through our servers to our geocoding provider (Geoapify), and cover-photo searches go to our photo provider (Unsplash). We don’t store these search queries on our own servers — only the place or photo you ultimately choose is saved to your trip.
  • Messages you send us. If you contact us through the in-app form, we store the message you write (its category, subject, and text) together with your email address, so we can read it and reply. We use it only to respond to you.

We do not collect analytics, usage tracking, or crash-reporting data, and we do not track your device’s real-time location in the background. The only location data we hold is the places you deliberately add to a trip.

Notifications. If you turn on notifications — trip reminders or budget alerts — the app schedules them as local notifications on your device. They’re created and delivered entirely on your phone from information you already entered (your trip dates, and the budgets and costs you set) — we don’t send them from our servers, and no notification data leaves your device. You can turn them off anytime in the app’s settings or in your phone’s settings.

How we use your information

We use the information above only to:

  • Sign you in and keep your account secure.
  • Store your trips and sync them across your devices so you can plan, view, and relive them.
  • Render your places on the map, and find places and photos you search for. Map coordinates are sent to our mapping provider (Mapbox) to draw the globe; place searches are sent through our servers to our geocoding provider (Geoapify) to return results; cover-photo searches are sent to our photo provider (Unsplash).
  • Respond to you if you contact us for support.

We do not show ads inside the app, we do not build advertising profiles about you, and we do not sell or rent your data to anyone. Some booking links in the app are affiliate links — see “Affiliate links” below for how those work.

Service providers

We rely on a small number of trusted providers to run the app. They process data only on our behalf and only as needed to provide their service:

  • Clerk — authentication and account management.
  • Microsoft Azure (Cosmos DB and Blob Storage) — secure storage of your trips and events (Cosmos DB) and of any documents you attach (Blob Storage).
  • Mapbox — map rendering and turning a tapped point into an address. It receives the coordinates needed to display your places on the globe.
  • Geoapify — place search. When you type to find a place, the text is forwarded through our servers to Geoapify, which returns matching results.
  • Unsplash — cover-photo search. It receives the text you type when searching for a trip cover photo. We store only the URL of a photo you choose, never a copy of the image.

Affiliate links

Some booking links in the app — for stays, activities, transport, transfers, eSIMs, or travel insurance — are affiliate links. They keep the app free: if you tap one and book on the partner’s site, we may earn a small commission, at no extra cost to you. This is optional and entirely your choice.

We do not share your trips or personal data with these partners. When you choose to tap an affiliate link, you leave the app and are sent — through our affiliate network, Travelpayouts — to the partner’s website. At that point Travelpayouts and the partner may set their own cookies or identifiers (for example, to credit the referral) and may collect data such as your IP address and the pages you view, under their own privacy policies, not this one. If you don’t tap a booking link, none of this applies.

Where your data is processed

Your trips and events, and any documents you attach, are stored in Microsoft Azure (Cosmos DB and Blob Storage) in the European Union. Some of our service providers — our authentication provider (Clerk), our mapping provider (Mapbox), our geocoding provider (Geoapify), and our photo provider (Unsplash) — process limited data, such as your account identifier, the coordinates of the places you add, or the text you type when searching, on servers in the United States. Where data is transferred outside the EU, it is protected by appropriate safeguards such as the providers’ Standard Contractual Clauses.

Data retention and deletion

We keep your account and trip data for as long as your account is active. You can delete individual trips, events, and documents at any time in the app. You can also permanently delete your entire account and all associated data directly in the app, under Settings → Delete account — this removes your trips and any attached documents from our servers and your identity from our authentication provider. When you delete a document, a trip, or your account, the associated files are removed and fully erased within a short period. If you’d rather we do it for you, email us at hello@liuliu.io and we will remove it.

Your rights

Depending on where you live (for example under the GDPR or CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these, contact us at hello@liuliu.io. We don’t sell personal data, so there is nothing to opt out of on that front.

Children

liuliu is not directed to children under 16, and we do not knowingly collect data from them. If you believe a child has provided us information, contact us and we will delete it.

Changes to this policy

If we change what we collect or how we use it, we’ll update this page and revise the “last updated” date above. For material changes, we’ll make a reasonable effort to notify you in the app.

Contact

Questions about this policy or your data? Email hello@liuliu.io.