Privacy Policy
Effective 20 August 2026 · Last updated 20 September 2026
SkyPass helps travelers create, save, and share trip plans. This policy explains the information SkyPass processes, why it is used, and the choices available to travelers.
Information SkyPass processes
Account information
When you sign in with Apple or Google, SkyPass receives the account identifier, display name, and email address made available by that provider. SkyPass uses this information to create and secure your account and synchronize your trips.
Profile and trip information
SkyPass may store information you choose to provide, including:
- Residential country and home city.
- Nationality, passport issuing country, and passport expiry date.
- Travel preferences such as interests, pace, budget, and dietary needs.
- Trip dates, destinations, accommodation details, reservations, itinerary items, checklists, saved places, and bucket-list selections.
- Trip invitations and membership information for shared trips.
SkyPass does not collect passport numbers, passport scans, legal names from a passport, dates of birth, payment-card details, or continuous background location history.
Location
When you explicitly request nearby suggestions, the app may send a one-time precise location to the SkyPass API and Google Places. SkyPass does not store a continuous location history. You can deny location permission and continue to use the app with reduced nearby functionality.
Diagnostics
SkyPass processes app version, build, operating-system version, device model, crash information, performance information, and structured error records to diagnose failures and improve reliability. Product diagnostics are designed to exclude authentication tokens, passport attributes, names, contact details, and full itinerary addresses.
Product analytics
SkyPass sends structured product-interaction events to Firebase Analytics and PostHog to understand feature use and improve the app. After sign-in, PostHog receives the opaque SkyPass user identifier and authentication-provider type so repeat use can be measured. Analytics events may also include app and device metadata and opaque trip identifiers. They do not include your name, email address, authentication tokens, passport details, document contents, booking references, or full itinerary addresses. PostHog automatic interaction capture, screen capture, session replay, and error capture are disabled.
Automatically received technical data
Hosting and service providers may receive standard network information, such as IP address, request time, user agent, and security logs, when the app connects to their services.
How information is used
SkyPass uses information to:
- Authenticate accounts and maintain sessions.
- Create, save, synchronize, and share trip plans.
- Personalize itinerary and place suggestions.
- Generate AI-assisted itineraries and place summaries.
- Provide nearby search, mapping, and place information.
- Detect abuse, apply rate limits, secure the service, and investigate errors.
- Measure product use and improve app features.
- Comply with legal obligations and enforce applicable terms.
SkyPass does not sell personal information, use it for third-party advertising, or track travelers across other companies' apps or websites.
AI-assisted features
Trip context needed to produce an itinerary may be sent through the SkyPass API to OpenAI. Provider usage records are designed not to store prompts or traveler review text. AI output can be incomplete or incorrect and should not replace official travel, entry, safety, medical, or legal advice.
Service providers
SkyPass uses service providers that process information on its behalf or provide content required by the app, including:
- Apple and Google for sign-in.
- Vercel for API hosting and operational logs.
- DigitalOcean for managed PostgreSQL hosting and backups.
- Google Maps Platform for maps, place search, details, photos, and reviews.
- OpenAI for AI-assisted itinerary and place-summary generation.
- Firebase Analytics for first-party product analytics.
- PostHog for first-party product analytics and feature configuration.
- Firebase Crashlytics for crash and performance diagnostics.
- Public information and media providers, including Open-Meteo and Wikimedia, when their content is requested by an enabled feature.
These providers process information under their own terms and privacy policies. SkyPass may also disclose information when required by law, to protect users or the service, or as part of a business transaction subject to appropriate safeguards.
Retention
Account and synchronized trip information is retained while the account is active or as needed to provide the service. The following shorter periods apply to operational copies:
- Firebase Crashlytics keeps crash traces and associated diagnostic identifiers for 90 days before beginning removal from live and backup systems.
- SkyPass structured diagnostics, API runtime logs, and security logs are not copied to a separate long-term log store. They remain available only for the Vercel plan's runtime-log window, never longer than 30 days.
- DigitalOcean creates a managed PostgreSQL backup once per day and retains backups for seven days. Data deleted from the live database may therefore remain in an encrypted backup for up to seven days before that backup expires.
Longer retention applies only when required by law or when a specific record must be preserved temporarily to investigate a security incident. Access to such a preserved record is restricted, and it is deleted when that need ends.
Your choices and rights
You can:
- Change optional profile information in the app where editing is available.
- Deny or revoke location access in iOS Settings.
- Delete individual trips.
- Delete your account in Profile > Delete account. Account deletion removes the server account and associated profile, sessions, owned trips, invitations, and local SkyPass data. Deleting an owned shared trip also removes access for its collaborators.
- Contact SkyPass to request access, correction, export, or deletion where applicable law provides those rights.
To make a privacy request, contact hello@sky-pass.ge. SkyPass may need to verify the request before acting on it.
Security
SkyPass uses measures intended to protect information, including encrypted HTTPS connections, hashed opaque sessions, least-privilege service roles, access controls, and redacted diagnostics. No system can guarantee absolute security.
International processing
SkyPass and its service providers may process information in countries other than your own. Where required, appropriate safeguards will be used for these transfers.
Changes to this policy
This policy may be updated as SkyPass changes. The updated policy will show a new effective date. Material changes will be communicated where required.
Contact
SkyPass
Email: hello@sky-pass.ge
Support: sky-pass.ge/support