Viala – Privacy Policy
Last updated: September 2026
This Privacy Policy explains how “we”, “us” processes personal data when you use the Viala mobile application (the “App”) and related services (the “Service”).
1) Controller and Contact
Email: Travelcompanionai@gmail.com
2) Which products / scope this covers
This Privacy Policy applies to:
- the App and all in-app functionality; and
- backend services required to operate the App (e.g., Firebase, Google Cloud, Weather API).
Firebase is used for the App backend only. A static marketing website (e.g., hosting this Privacy Policy and the Terms of Use) may be hosted separately. When you access such a page, the hosting provider may generate server access logs. No additional interactive website is operated for the App at this time. If this changes, this policy will be updated accordingly.
3) Personal data we process
3.1 Account and profile data (provided by you)
- Account data: email address; authentication identifiers (Firebase user ID); login metadata.
- Sign-in provider data: if you use Google Sign‑In or Sign in with Apple, we process the provider user identifier and basic profile information provided by that provider to enable authentication. For Sign in with Apple, the email address may be a Private Relay address generated by Apple. We treat both sign-in methods in parallel.
- Profile data: a display name (currently required at registration, but freely chosen by you and not required to be your real name), profile photo (optional upload), and an invite ID — a unique, randomly generated identifier created by the App and stored in your account profile, used so other users can find and invite you to collaborate on trips. The invite ID is searchable by any authenticated user of the App. You can regenerate your invite ID at any time from Profile → Personal Details (limited to once per day). Regeneration assigns a new random invite ID, makes the old ID unfindable, and silently declines any pending inbound share invitations that referenced the old ID. Trip collaborators you have already accepted are unaffected.
- Home base (optional): you can optionally set a home city in Profile → Personal Details to personalise trip suggestions and pre-trip guidance. We store the city name you select and its Google Places identifier; we do not store your device's live location or coordinates for this. You can change or remove it at any time.
- Support communications: if you contact us, the content of your message and related contact data.
- Content/abuse reports: if you submit a report via Help & Support → "Report Content or Abuse", we process the data you provide (selected category, free-text description, optional reference such as a trip ID or share code), your account identifier (reporter), and basic device metadata (app version, build number, platform, locale) so our team can review and act on the report.
3.2 Trip and collaboration data (created by you / through your use)
- Trip content: destinations, dates, budgets, trip expense entries (amounts, optional descriptions), interests, preferences, saved itineraries, notes and similar user inputs.
- Collaboration/sharing data: trip membership, collaboration invitations (including accept/decline status), and the trip's shareable import code (a short alphanumeric code, if you enable import sharing for a trip) used for QR-based trip copying. Change and sync data required for real-time collaboration is also processed.
- Social interactions: invitations, accept/decline, leaving a trip, and similar “social” events.
3.3 Technical and device data
- Device/app data: app version, OS version, device model class, language, timestamps, and technical identifiers needed to operate the Service.
- Firebase Installation ID (FID) / app instance identifiers: used by Firebase to operate services such as Messaging, Crash reporting and Analytics.
3.4 Crash reporting (Crashlytics)
Crashlytics is enabled by default to help us detect and fix stability issues. It processes crash reports and diagnostic data, including: stack traces, app version, device model class, OS version, and app/device state at the time of the crash.
We do not set any custom user identifiers in Crashlytics. Crash reports are therefore not directly linked to your account. Crashlytics uses a Firebase Installation ID (FID) — a randomly generated identifier tied to the app installation, not to your account — for crash deduplication and grouping. Firebase manages FID rotation automatically.
3.5 Analytics (Firebase Analytics) – opt-in, consent-based
Firebase Analytics is disabled by default. It is only enabled if you explicitly consent via an in-app prompt. You can withdraw consent at any time in the app settings, which will disable further data collection.
If you consent, Firebase Analytics processes coarse, non-user-specific usage events to help us understand how the App is used and improve it. We collect only high-level, aggregated events such as feature usage patterns (e.g., trip created, Nearby search run, AI generation initiated, QR import used, invite sent) and aggregate error counters. We do not log free-text trip content, personal inputs, or any user-identifiable data through analytics.
We also collect screen views (e.g., which screens you visit and in what order) to understand navigation patterns and improve the user experience. Screen names are generic (e.g., "Trip Detail", "Home", "Profile") and do not include trip content, personal data, or identifiers.
- Advertising ID / IDFA: We explicitly disable advertising identifier (Android Advertising ID / iOS IDFA) collection. Analytics data is not used for advertising or profiling.
- Depending on platform, analytics may use an app instance identifier (a randomly generated identifier, reset when the app is reinstalled), which is not linked to your account.
3.6 Push notifications (Firebase Cloud Messaging – FCM)
If notifications are enabled on your device, we process:
- a push token (device token) and technical metadata needed to deliver notifications.
We use notifications for:
- collaboration invites and trip updates (e.g., invite accepted, updates, leaving a trip); and
- important service messages (e.g., feature updates relevant to the Service, maintenance or incident notices).
We do not need your email to send push notifications. You can disable notifications via device settings.
If we ever add marketing notifications, we will provide a separate opt‑in control.
3.7 Location data (What's Nearby and home screen) – optional, permission-based
If you use What's Nearby and grant permission, the App may access your device location (coordinates) to determine your current city via reverse geocoding.
If you have set a home base and have already granted location permission, the App additionally reads your device's last known position when the home screen is shown, in order to display context-aware suggestions (for example, whether you are currently away from your home city).
- No request from the home screen: the App never asks for location permission on the home screen. If permission was not granted, or no recent position is available, this feature is silently skipped and the home screen shows non-location-based suggestions instead.
- Control: you can deny location permission and still use the App by entering a city manually.
- Storage: we store only the derived city (e.g., “Bonn”), never your raw coordinates — including for the home-screen check.
Geocoding: Converting coordinates into a city name is performed by your device's operating system (Google on Android, Apple on iOS), not by our backend. We do not store or transmit raw coordinates ourselves.
3.8 Camera access (QR trip import)
If you use QR import, the App uses camera permission to scan QR codes and import trip data. We do not record video and do not store camera images unless your OS forces temporary buffering.
3.9 Mandatory vs. optional data (Art. 13(2)(e) GDPR)
Some data is necessary to use the Service; other data is optional:
Mandatory (required for the Service to function in the current app version):
- Email address and authentication credentials: required to create an account and log in.
- Display name: currently required during account registration. You may choose a pseudonym or other non-real-name label.
- Firebase user ID and Firebase Installation ID: generated automatically as technical necessities.
Optional (you can use the Service without these):
- Profile photo: optional; all features work without it.
- Home base (city): optional; personalises trip suggestions and pre-trip guidance. You can set, change, or remove it anytime in Profile → Personal Details.
- Location permission (What's Nearby): if denied, you can enter a city manually instead, and the home screen shows non-location-based suggestions.
- Camera permission (QR import): if denied, the rest of the App is unaffected.
- Notification permission: if declined, the App still works; you will not receive push notifications.
- Analytics consent: declining does not affect any App functionality.
Consequences of not providing data: Declining optional permissions or data does not prevent you from using the App overall. The specific feature relying on that data will not be available (e.g., no GPS-based city prefill without location permission), but all other features remain accessible.
3.10 Place signals from your use of the app
We record how you respond to place suggestions (viewed, saved, liked, or imported from a shared link) together with basic trip context, under a pseudonymous account ID. This is processed only in aggregate per place — never as an individual profile — to rank and label suggestions (e.g. "Trending"), and never for advertising.
Shared links: when you share a social-media post (currently TikTok) into Viala, we read its public caption to identify the places it mentions. We keep the link, identified places, and your account ID for 90 days to avoid counting the same post twice.
4) Purposes and legal bases (GDPR Art. 6)
We process personal data for the following purposes:
- Provide the Service / perform the contract (Art. 6(1)(b))
- account creation and login
- saving trips and preferences
- collaboration/sharing and QR import
- push notifications for invites and trip updates
- weather feature and maps display
- personalising trip suggestions and pre-trip guidance from your optional home base
- AI-assisted generation of itineraries and recommendations (Art. 6(1)(b))
- we process trip inputs and context to generate recommendations via Google Cloud / Vertex AI (Gemini).
- Location-based features (What's Nearby, home-screen context) (Art. 6(1)(b), plus OS permission)
- location is used when you actively use What's Nearby, and — only if you have set a home base and already granted permission — to determine on the home screen whether you are currently away from your home city.
- Security, abuse prevention, and service integrity (Art. 6(1)(f))
- access controls, fraud/abuse prevention, minimal technical logs.
- handling user-submitted content/abuse reports so we can review, investigate, and act on objectionable content or behavior in the Service.
- App stability and debugging (Art. 6(1)(f))
- crash reporting (Crashlytics, enabled by default) to identify and fix crashes. Our legitimate interest is providing a stable, functioning service.
- Analytics / product improvement (Art. 6(1)(a) – consent)
- Firebase Analytics is only enabled with your explicit in-app consent. You can withdraw consent at any time.
- In Germany/EU, access to non-strictly-necessary device information requires consent under § 25 TDDDG.
- Operate and secure hosted legal pages (Art. 6(1)(f))
- Hosting provider access logs for security, abuse prevention, and reliable delivery of hosted legal documents (e.g., this Privacy Policy and Terms of Use).
- Legal obligations (Art. 6(1)(c))
- if we are legally required to retain or disclose certain data.
- Improving suggestions from aggregated usage signals (Art. 6(1)(f))
- we aggregate how place suggestions are shown and responded to (Section 3.10) to rank and label places for all users. Legitimate interest: relevant, current suggestions; data is pseudonymous, evaluated only per place, never used for profiling or advertising.
No solely automated decisions with legal or similarly significant effects: the Service provides suggestions; users decide.
5) Recipients and third-party services
We use the following service providers. Depending on the product, they act as processors and/or independent controllers.
5.1 Other users (collaboration)
If you share a trip with another user:
- collaborators can see your display name and profile photo (if you set one), and
- the shared trip content.
5.2 Google and Apple (identity providers)
If you sign in using Google Sign-In or Sign in with Apple, the respective provider processes authentication-related data as an independent controller under their own privacy policies. We receive only the identifiers and basic profile information necessary to authenticate you and link the login to your App account.
5.3 Google Firebase (Auth, Firestore, Functions, Storage, Messaging, Analytics, Crashlytics)
We use Firebase to operate the Service. Firebase typically acts as a processor for customer data under the Firebase Data Processing and Security Terms.
5.4 Google Maps Platform (Maps, Places, Directions)
We use Google Maps Platform for map display, place search, and routing. For certain data, Google provides controller‑controller terms indicating each party acts as an independent controller.
5.5 Google Cloud / Vertex AI (Gemini)
We use Google Cloud / Vertex AI to generate AI-assisted recommendations. Google provides a Cloud Data Processing Addendum/terms for customer personal data under applicable agreements.
What we send to the AI: Prompts sent to Vertex AI (Gemini) contain only trip planning inputs: destination, travel dates, number of participants, companion type (e.g., solo, couple, family), budget level, and selected interest categories. We do not send account data — no name, email address, user ID, invite ID, or profile photo is included in AI prompts.
Backend logging: Our Cloud Functions log only operational metadata (prompt character length, response length, timing, and finish reason). Prompt content and response content are not logged, except that if the AI returns an unparseable response, the first 500 characters of that raw response (which may include travel details derived from your inputs) may be logged temporarily for debugging.
5.6 WeatherAPI.com (weather)
When you use the weather feature, we send the destination city to WeatherAPI.com to retrieve weather data.
Implementation: weather requests are executed server-side (backend), so WeatherAPI generally receives backend request metadata (e.g., server IP address), not your device IP address.
5.7 App store providers
Google Play and the Apple App Store process data as independent controllers when you download or update the App.
6) International data transfers
Your primary Firebase region is europe-west3. Some services (especially AI) may process data globally depending on provider infrastructure.
If providers process data outside the EEA, they typically rely on lawful transfer mechanisms (e.g., EU Standard Contractual Clauses and/or adequacy mechanisms where applicable).
We will keep this section aligned with the configurations and provider contracts in place.
7) Retention and deletion
7.1 Retention
We retain personal data only as long as necessary for the purposes above. Typical retention logic:
- Account and profile data: while your account is active; deleted from active systems upon account deletion (subject to backups per Section 7.3).
- Trips and collaboration data: while needed to provide the Service; see Section 7.2 for what happens on account deletion.
- Rate-limiting counters: automatically expire after 2 days from creation.
- Collaboration invitations (share requests): deleted from active systems upon account deletion (subject to backups per Section 7.3).
- Crash reports (Crashlytics): 90 days.
- Analytics data: 14 months (only applies if you have consented). Analytics data is deleted automatically after 14 months; for active users, the retention period resets on new activity, so their data is retained as long as they use the Service. Aggregated statistics that no longer relate to an identifiable person may be kept longer.
- Server logs / security logs: 90 days.
- Share requests: automatically expire after 7 days.
- What's Nearby sessions: automatically expire after 14 days.
- Trip data with the direct account link removed (after account deletion): automatically deleted after 180 days.
- Content/abuse report records: retained while your account is active and may be retained longer if attached to an open moderation case (e.g., to preserve evidence for review or enforcement). The internal email-outbox copy used for notification is automatically deleted after 7 days.
- Place signal events (Section 3.10): automatically deleted after 90 days; deleted from active systems upon account deletion. The anonymous per-place aggregate derived from them (counts per place, not attributable to a person) is retained.
- Shared-link import records: automatically expire after 90 days; deleted upon account deletion.
7.2 Account deletion and remaining content
You can delete your account via the in-app feature (Settings). If you no longer have access to the app, you can request deletion via our web form at https://viala-ai.com/delete-account/.
If you delete your account via the in-app feature, the following happens immediately:
Deleted from active systems (residual copies may remain in encrypted backups until overwritten — see Section 7.3):
- Your user profile (email, display name, profile photo, invite ID, login metadata, notification preferences)
- Your profile image from storage
- All your in-app notification records
- Your What's Nearby session data
- All collaboration invitations (share requests) you sent or received
- Your Firebase Authentication record (login credentials)
Account deletion and remaining trip content
When you delete your account, your account/profile data, profile image, notifications, What's Nearby sessions, share requests, and Firebase Authentication record are deleted from active systems. Trip planning requests, trip itineraries, and saved activities you created may remain for up to 180 days with the direct account link removed. Your user ID is replaced with an anonymous placeholder. These records are automatically deleted after 180 days.
Collaborations on other users' trips:
If you were a collaborator on another user's trip, your user identifier is removed from that trip's access list. The trip and its content remain accessible to the trip owner.
Import codes:
If you had enabled trip sharing via import code, the import code may remain attached to the trip document with the direct account link removed. It is no longer linked to your identity after account deletion.
Place signals and shared-link imports:
Place signal events and shared-link import records linked to your account are deleted; the anonymous per-place aggregates they contributed to remain, as they cannot be attributed to you.
7.3 Backups
Residual copies may remain in encrypted backups for up to 90 days before automatic deletion.
8) Your rights
You have rights under the GDPR, including:
- access, rectification, erasure,
- restriction, data portability,
- objection where processing is based on legitimate interests,
- withdrawal of consent where processing is based on consent,
- complaint to a supervisory authority.
You can contact us at Travelcompanionai@gmail.com.
9) Security
We implement appropriate technical and organisational measures (e.g., access controls, encryption in transit, Firebase security rules, least-privilege IAM) to protect personal data.
10) Permissions and controls
Depending on features you use, the App may request:
- Location permission (What's Nearby; also read on the home screen if already granted),
- Camera (QR import),
- Notifications (push).
You can disable permissions in device settings. Some features may not work without the relevant permission.
11) Children / age limitation
The Service is not intended for children under 16. We do not knowingly process personal data of children under 16.
If you believe a child under 16 has provided personal data, contact us and we will take appropriate steps.
12) Changes to this Privacy Policy
We may update this Privacy Policy due to changes in law, technology, or features. The current version will be available in the App and/or at the URL provided in the app store listing: https://viala-ai.com/privacy/.