TripSync Privacy Policy
Last updated: 10th September, 2026
TripSync ("we", "us") is built and operated by Akshit Grover and Saurav Bhagat, working as independent developers — TripSync is not offered by a company or other registered legal entity. TripSync is currently offered only to users located in India. This policy explains what we collect, why, and your choices — with special attention to face data, which is sensitive personal data under Indian law.
1. Information we collect
- Account info: phone number (phone login), and/or name and email (Google / Apple sign-in).
- Face data (biometric): only if you choose to create a "Face Profile." See Section 3 for full details.
- Photos: photos you upload to a group, plus basic metadata (dimensions, file size, upload time).
- Usage & device data: app interactions, device/OS info, push notification tokens, and diagnostic logs.
2. How we use it
- To run the core feature: automatically sorting each group's photos to the people who appear in them.
- To authenticate you and secure your account.
- To send you notifications about your groups (for example, when someone adds photos).
- To screen uploaded photos for objectionable content, and to act on reports and blocks (see Section 7).
- To operate, maintain, debug, and improve the service.
3. Face data (biometric information)
What we collect. Creating a Face Profile is optional. If you choose to create one, we collect (a) the reference selfie you capture with the camera or select from your library, and (b) a mathematical face template ("face vector") generated from that selfie by Amazon Rekognition. Amazon Rekognition stores the template in our face collection and returns an opaque identifier; we store only that identifier, not the template itself. Separately, for each photo uploaded to a group we store face bounding-box coordinates and the match result (which member matched, and a similarity score) — these are coordinates and account identifiers, not biometric templates.
How we use it. Face data is used for one purpose only: to automatically identify which photos inside your own invite-only TripSync groups include you, so that those photos appear in your "My Photos" view. We do not use face data for advertising, profiling, identity verification, surveillance, or to identify anyone outside your own groups. We do not use face data to train any machine-learning models; Amazon Rekognition processes it solely to perform the matching we request, as our processor.
Sharing. We do not sell your face data, and we do not share it with any third party for that third party's own purposes. It is processed only by Amazon Web Services (Amazon S3 and Amazon Rekognition) acting as our service provider. No advertising or analytics provider receives face data.
Storage. Your reference selfie is stored in a private, encrypted Amazon S3 bucket, accessible only through short-lived signed links. Your face template is stored in an Amazon Rekognition face collection. Both are hosted in AWS region [REGION]. Related identifiers and match results are stored in our database (MongoDB Atlas).
Retention. We retain your reference selfie and face template only for as long as your Face Profile exists. Face templates created temporarily in order to scan an uploaded group photo are deleted immediately after the match completes. Face match results (a bounding box and which member matched) are retained with that photo for as long as the photo exists.
Deletion. You can delete your face data at any time. Replacing your Face Profile deletes the previous template. Deleting your account (Profile → Delete Account) permanently deletes your reference selfie from Amazon S3 and your face template from Amazon Rekognition, together with your account data.
Consent. We collect and process your face template only with your consent, given when you create a Face Profile. You can decline — you will still see your group's photos, they simply won't be auto-sorted to you. You can withdraw consent at any time by deleting your Face Profile or your account.
Indian law. Under India's Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, biometric information (including your face template) is Sensitive Personal Data or Information (SPDI). We collect and process it only with your explicit, opt-in consent, we do not use it for any purpose beyond matching you to your group photos, and you can withdraw consent at any time.
4. How photos and identity are shared
- Photos you upload are visible to members of that group (invite-only). They are not public and are not indexed by search engines.
- Photos are served to members through short-lived signed links.
- We do not sell your personal data.
5. Service providers
We use service providers (processors) who handle data on our behalf:
- Amazon Web Services — photo and selfie storage (Amazon S3), face detection/matching and content-moderation screening (Amazon Rekognition).
- MongoDB Atlas — our database.
- Twilio — sending one-time codes by SMS.
- Apple Push Notification service, via Expo — delivering push notifications.
- Google and Apple — sign-in, if you choose those options.
- PostHog — product analytics (app interactions and device/diagnostic data; never face data or your photos).
- Unsplash — default group cover images, chosen from your group name.
6. Data retention
- Account info, face template, and reference selfie: deleted immediately when you delete your account.
- Temporary face templates used to scan a photo: deleted immediately after matching.
- Photos you shared to a group: these belong to that group because you chose to share them there, so they remain in the group after you leave or delete your account. They are simply no longer tied to your identity — you stop being tagged or matched to them, and they remain visible to members of that group only, same as before.
- Photos you remove: removing a photo removes it from your own library; other members keep their copies.
- Storage limits: if you exceed your storage allowance, photos you add after that point remain available to view and download for 7 days, after which they are removed from your account unless you free up space. Other members' copies are unaffected.
- Reports and blocks: we retain a record of reports and blocks so we can review abuse and enforce our terms.
7. Content moderation, reporting and blocking
- Every photo uploaded is automatically screened for objectionable content using Amazon Rekognition. Photos detected as explicit, violent, visually disturbing, or containing hate symbols are rejected and are not shown to anyone.
- Any member can report a photo, or block another member, from inside the app. Reporting removes the photo from your library immediately; blocking immediately removes that member's photos from your groups and notifies us so we can review the account.
- We review reports and blocks within 24 hours, remove violating content, and suspend or terminate accounts that breach our Community Guidelines or Terms of Use.
8. Your rights & choices
- Delete your account anytime in-app (Profile → Delete Account): this removes your account, face template, and reference selfie, and removes you from all groups.
- Leave a group anytime: you lose access to that group's photos and are untagged there.
- Withdraw face-data consent anytime by deleting your Face Profile or your account.
- Access, correction & erasure: under India's Digital Personal Data Protection Act, 2023 (DPDPA), you can ask us to confirm what personal data we hold about you, correct or complete it, or erase it (including withdrawing consent to your Face Profile at any time, without affecting the lawfulness of processing before withdrawal). You can also register a grievance about how we've handled your data. To do any of this, contact the.creative.act108@gmail.com; we aim to acknowledge requests within 24 hours and resolve them within 15 days.
9. Security
Data is encrypted in transit (TLS) and at rest (S3 encryption). Photos and selfies are stored in private buckets and served only through short-lived signed links. Access is restricted to authorized systems and personnel. No method is 100% secure.
10. Where your data is processed
TripSync is offered only to users in India, and we do not offer the app in the EU, UK, US, or other regions. Your photos, reference selfie, and face template are stored in AWS region [us-east]. Some of our service providers — for example Amazon Web Services — may process or store data outside India as part of running their infrastructure. Where that happens, we still require our service providers to protect it consistent with this policy.
11. Children
TripSync is intended for users who are 18 or older. Under the DPDPA, anyone under 18 is a "child," and processing a child's personal data — including creating a Face Profile — requires verifiable consent from a parent or lawful guardian. TripSync does not currently support that consent flow, so the app is not directed to, and may not knowingly be used by, anyone under 18. If we learn an account belongs to someone under 18, we will delete the account and associated data.
12. Changes
We may update this policy; we'll post the new date and, for material changes, notify you in-app.
13. Contact
TripSync is built and run by two independent developers, not a registered company, so there's no company name or office address to list here. For anything about this policy, your data, or how a report or complaint was handled, write to the.creative.act108@gmail.com, or reach us directly:
- Akshit Grover — akgrover.contact@gmail.com
- Saurav Bhagat — sauravbhagat088@gmail.com