Privacy Policy
Joru is a travel planner whose AI runs on your device. This policy explains what data the app handles, what stays on your phone, what leaves it and why, and the controls you have. Plain language first, details below.
Last updated: 9 August 2026 · Applies to the Joru app for Android and iOS
The short version
- Your trips stay on your device. Nothing is uploaded unless you turn on sync.
- The AI is on-device. Your preferences and itineraries are never sent to a cloud AI provider.
- Facts come from open data. To find real places, weather and maps, the app sends the destination or map area (a city name or coordinates) to open services — not your saved trips or traveller details.
- Usage analytics are opt-in and off by default. Crash reports are on by default (to keep the app stable) and you can turn them off anytime. No ads. No cross-app tracking. We never sell your data.
- You're in control: export all trips, erase all local data, disable sync or turn analytics off — at any time.
Data controller
Joru is developed and published by Raúl Corvo Uña, NIF 48335156N — Av. Maisonnave 41, 3.º B, 03003 Alicante, Spain. For any privacy question or data request: corvo.ai.studio@gmail.com. Joru is operated by an individual developer based in Spain (EU).
Data you enter, kept on your device
To build a plan, Joru uses the details you provide in the trip form and while using the app. These are stored locally on your device and are not sent anywhere unless you explicitly enable sync (see below):
- Trip destinations and dates.
- Number of travellers and, optionally, children's ages (used only to tailor the plan).
- Preferences: pace, interests, budget, cuisine and dietary needs, mobility, accommodation and transport choices.
- Your generated itineraries, real-spend entries and packing checklists.
Joru does not require an account to plan trips, and does not ask for your name, phone number or contacts.
Open-data services the app contacts
Joru is not an “offline” app: to keep every place, guide and forecast real, it fetches facts from open data over the network. To do that it sends the destination or map area (a place name, a search query or coordinates) to the services below. It does not send your saved trips, traveller details, budget or other personal preferences to them. As with any web request, these services receive your device's IP address and process it under their own policies.
- OpenStreetMap / Overpass — real places and points of interest.
- Nominatim (OpenStreetMap) — turning a place name into coordinates.
- Wikivoyage / Wikipedia — area guides, place descriptions and images.
- Open-Meteo — weather for your destination and dates.
- Stadia Maps — interactive map tiles when you open the map.
- Frankfurter (European Central Bank rates) — converting your budget between currencies. Only the two currency codes are sent, never an amount.
- GitHub — Joru downloads a pre-built map extract of the region you are planning (a file of tens of MB, cached on your device so it is fetched once per region). Only the file name of the region is requested; no trip information is sent.
Map data © OpenStreetMap contributors (ODbL); guides from Wikivoyage (CC BY-SA); forecasts from Open-Meteo. The AI model runs locally on your device — your preferences and itinerary are never sent to a cloud AI provider.
Sign-in, sync, analytics and purchases
These features send data off your device, so each one is optional and, where required, asks for your consent.
Sync with your own cloudOptional
If you turn on sync, Joru saves a copy of your trips to your own cloud storage — Google Drive on Android, iCloud on iOS. Never to a server of ours: we have no backend and never receive a copy of your trips.
- Google Drive: the copy goes to the private app storage of your Drive — Joru can only see files it created and cannot read the rest of your Drive. Your access token is kept in the device's secure storage, never in plain text. You can disable sync or revoke Joru's access from your Google Account at any time.
- iCloud: the copy goes to your own private iCloud database, tied to your Apple Account and inaccessible to us. You can disable sync in the app, or remove Joru's data from iCloud in your device settings.
In both cases the snapshot is encrypted before upload.
Sign-inOptional
Signing in is only used to enable sync, and only with the provider for your platform: Google Sign-in on Android and Sign in with Apple on iOS. Joru receives a basic account identifier and an authorisation token for the storage; it does not post anything to your account or read your other data. Sign in with Apple lets you hide your email address if you prefer.
Crash reports & usage analyticsFirebase
Joru uses Google Firebase for two separate things, with two separate controls in Settings:
- Crash reports — on by default (legitimate interest). When the app crashes, Firebase Crashlytics collects diagnostic device information and a stack trace so we can fix the bug. This contains no behavioural tracking and is not tied to your name or used for advertising. You can turn it off anytime in Settings.
- Usage analytics — opt-in, off by default. Anonymous in-app events that help us improve the app. This only starts if you turn it on — either from the one-time prompt on first launch or the toggle in Settings — and you can turn it off again anytime.
Neither uses your advertising ID. The app also uses Firebase Remote Config to adjust settings (such as the on-device model), which does not require personal data.
On iOS, if you turn usage analytics on, the system's App Tracking Transparency prompt is shown first — and only then; if you leave analytics off, Joru never asks. Joru does not track you across other apps or websites in any case.
Premium purchasesOptional
Premium (a monthly subscription or a one-time purchase — what each covers is set out in the Terms of Use) is handled by the store you installed from — Google Play Billing on Android, the Apple App Store on iOS — together with RevenueCat, which unlocks your entitlement across your devices. RevenueCat receives an anonymous app-user identifier and the purchase token; we never receive your payment card details — those are handled entirely by Google or Apple.
Affiliate links
Once your plan is ready, Joru may show links to trusted travel partners (for stays, tours & tickets, car rental, airport transfers, eSIM data, travel insurance, trains & buses). These are clearly labelled as “affiliate link”. There is no advertising SDK and no tracking before you click. If you choose to open one, the partner's website may set its own cookies and identifiers under its own privacy policy, and we may earn a small commission at no extra cost to you — which keeps the free version free. Partners are reached through networks such as Travelpayouts, Impact and Amazon Associates.
Data summary
| Data | Why | Where it lives | Basis |
|---|---|---|---|
| Trip details & preferences | Build your itinerary | On your device | Providing the service |
| Destination / map queries | Fetch real places, weather, maps | Sent to open-data services | Providing the service |
| Region name | Download the offline map extract | Sent to GitHub; file cached on device | Providing the service |
| Trips backup | Sync across your devices | Your own Google Drive or iCloud (encrypted) | Your consent |
| Account token | Enable sync | Device secure storage | Your consent |
| Crash reports | Fix bugs, keep the app stable | Firebase Crashlytics | Legitimate interest (opt-out) |
| Usage analytics | Improve the app | Firebase (if enabled) | Your consent (opt-in) |
| Purchase token | Unlock Premium | Google Play or App Store, & RevenueCat | Providing the service |
Control and legal bases
Joru is built in the EU and follows the GDPR. Our legal bases are: performance of the service for core planning; your consent for sync and usage analytics (which you can withdraw at any time); and legitimate interest for crash reports, which keep the app stable and which you can turn off in Settings. We follow data minimisation — we don't collect more than a feature needs.
There is no automated decision-making that produces legal or similarly significant effects about you: the on-device AI arranges a travel itinerary, nothing more. We do not sell personal data, and we do not build advertising profiles.
You can exercise your rights directly in the app, without contacting anyone:
- Access & portability: export all your trips from the app.
- Erasure: open Settings → Data → “Delete all local data” in the app to wipe everything stored on the device (trips, expenses, packing lists and preferences). Disabling sync and deleting the backup removes the synced copy from your own Drive or iCloud.
- Withdraw consent / object: turn usage analytics or crash reports off, or disable sync, in Settings at any time.
You may also contact corvo.ai.studio@gmail.com for any request. If you are unhappy with how we handle it, you have the right to lodge a complaint with your local data protection authority — in Spain, the Agencia Española de Protección de Datos (aepd.es).
How long, and how it's protected
- On your device: kept until you delete it (per trip, or all at once).
- Cloud backup: kept in your own Google Drive or iCloud until you delete it or turn off sync.
- Crash reports: retained by Firebase Crashlytics per Google's retention settings; on by default, stops when you turn it off. Usage analytics: only exists if you opted in.
Snapshots are encrypted before upload, access tokens are stored in the device's secure keystore, and all network traffic uses HTTPS. Some services above (Google/Firebase, RevenueCat, Stadia Maps, GitHub and the open-data providers) may process requests on servers outside the EU. Those transfers rely on the providers' own safeguards — an adequacy decision (such as the EU–US Data Privacy Framework) or the European Commission's Standard Contractual Clauses. Each provider is an independent controller of the request data it receives, under its own privacy policy.
Not directed to children
Joru is a general-audience travel planner and is not directed to children. You may enter children's ages when planning a family trip; this is used only to tailor the itinerary, stays on your device, and is never used to profile a minor or for advertising.
Plans are AI-generated
Itineraries are drafted by an on-device AI model, which arranges and describes real candidates from open data. Plans may contain errors and are not professional travel advice — please verify opening hours, prices and availability before you travel.
Changes to this policy
If this policy changes, we'll update the date at the top and, for significant changes, note it in the app. Continued use after an update means you accept the revised policy.
