Public page overview

These pages are written to be readable first: the operating details stay intact, but the presentation is organized so visitors can scan, understand, and find the right next step without digging.

13 sections

Section 01

Language versions

This English version is the primary public privacy notice for Fichi. A German version is available at /datenschutz.

01

Section 02

Data controller

Casal Software Manufaktur, operated by Jesus Casal is responsible for the processing of personal data related to Fichi. Contact: Mariannenstraße 108, 04315 Leipzig, Germany. Email: support@fichi.app.

02

Section 03

What we collect

03
  • Account information such as your email address, authentication details, and user identifiers.

  • Profile and trip information such as preferences, destinations, route details, itineraries, saved selections, and trip planning inputs.

  • Content you share into Fichi for trip planning, such as images, screenshots, and videos (including any audio they contain), which we process to extract travel details.

  • Support and feedback information such as messages, screenshots you choose to upload, and related account context.

  • Technical and usage information such as device, browser, log, security, and error data needed to operate and protect the service.

  • External booking interaction data when you click out to third-party travel providers.

Section 04

How we use your information

04
  • To provide the Fichi beta, including sign-in, trip planning, saved selections, and account management.

  • To improve performance, troubleshoot issues, prevent abuse, and keep the service secure.

  • To respond to support requests, feedback submissions, and account-related questions.

  • To comply with legal obligations and enforce our terms.

Section 05

How we protect your data

No method of transmission or storage is completely secure, but we use reasonable technical and organizational measures to protect your information.

05
  • Encryption in transit (HTTPS/TLS) for all traffic between your device and our services.

  • Encryption at rest for stored data through our managed database provider (Supabase).

  • Row-level security on database tables with a default-deny posture, so records are only accessible to the authenticated account they belong to.

  • Authentication through Supabase using short-lived bearer tokens, with sign-in via email and password, Google, or Apple.

  • Rate limiting and abuse-prevention controls to protect the service from misuse.

  • Access to production systems is limited to authorized personnel.

Section 06

Payments during beta

Fichi is currently free during beta. Payments and subscriptions are not live at this time. If paid billing is introduced later, this privacy notice will be updated accordingly.

06

Section 07

Cookies and analytics

Fichi uses essential cookies and similar storage for sign-in, session handling, and core product functionality. Optional browser analytics are used only after a positive consent choice. You can change that choice later through the product's consent controls when available.

07

Section 08

Third-party services

08
  • Supabase for authentication, database, and file storage.

  • Anthropic for AI-assisted trip planning features.

  • OpenAI for transcription and text recognition on content you upload, such as shared trip screenshots.

  • Twelve Labs for analyzing shared video content to extract travel details.

  • Langfuse for monitoring and tracing of AI features.

  • Google for sign-in and certain places-related features.

  • Open-Meteo for weather data.

  • Carto for map tiles.

  • Sentry for error monitoring and service reliability.

  • PostHog for product analytics where enabled and permitted.

  • Resend for transactional emails when email features are enabled.

  • Upstash Redis for rate limiting and abuse prevention.

Section 09

Third-party travel providers

Fichi may show or link to external travel providers such as airlines, hotel partners, or booking platforms. Any reservation is completed with the relevant third party, and that provider is responsible for its own payment, fulfillment, and privacy practices.

09

Section 10

International transfers

Some of the service providers we use may process data outside your country, including outside the European Union. Where required, we rely on appropriate safeguards provided by those vendors.

10

Section 11

How long we keep data

11
  • Account, profile, trip, and support data are generally kept for as long as your account remains active or as needed to provide the service.

  • If you ask us to delete your account, we will remove or anonymize data from our systems where reasonably possible, subject to legal, security, and operational requirements.

  • Certain abuse-prevention and rate-limit records may be retained for up to 90 days.

  • Information stored locally in your browser remains there until it is cleared, overwritten, or removed by the app.

Section 12

Your rights

Depending on where you are located, you may have rights to access, correct, delete, restrict, or object to certain processing of your personal data, and to request a copy of the personal data we hold about you.

12

Section 13

Contact

For privacy questions, access requests, or deletion requests, contact support@fichi.app.

13