Privacy policy
Last updated 2 August 2026
JA! Reisen is a group-trip planner. Your trip content — itinerary, checkpoints, expenses, display name and live positions — is end-to-end encrypted on your device before it leaves it. The server stores only ciphertext and the minimum metadata needed to route it between the members of a trip.
What we store
- An anonymous account id created on first launch, and your device's public keys.
- Encrypted trip blobs and the sealed keys that let members decrypt them.
- Push-notification tokens, used only to send content-free "something changed" pings. To deliver them we share the token with the platform push service — Apple Push Notification service (iOS) or Google Firebase Cloud Messaging (Android) — neither of which ever receives any trip content.
- An optional profile picture, if you upload one. Unlike your trip content this is not end-to-end encrypted — it is stored as-is and is visible to the other members of your trips. You can remove it at any time from Settings.
- Short-lived request logs (IP, path, timing) for rate limiting and abuse protection.
What we don't store
We never see plaintext itineraries, expenses, names or locations, and we don't store position history — only the last-known encrypted fix while a trip is live. There are no ads and no third-party trackers, and we do not sell data.
Location
Your location is captured only while you actively share it on a trip. You can pause sharing per trip, or turn it off entirely from Settings, at any time. Positions are encrypted before publish and are not retained as history.
Optional Google sign-in
Accounts are anonymous by default. You can optionally link a Google account so your trips can be recovered on a new device. If you do, we store your Google account identifier to match you on sign-in; this links your data to that Google account. Your trip keys are also backed up on the server for recovery — encrypted under a recovery passphrase only you know, so we cannot read them. If you skip setting a passphrase, that backup instead uses a key derived from your Google identifier, which someone with database access could in principle derive; set a recovery passphrase (in Settings) to make it fully zero-knowledge. Anonymous accounts have no such backup.
Retention
We keep little and purge aggressively: revoked/expired invites and their sealed keys, deleted (tombstoned) records, and archived trips are all removed automatically after a short, bounded window.
Your choices
Delete a trip to erase its encrypted content for everyone. To delete your account and all associated data, see How to delete your account.
Contact
Questions about privacy? See Support.