Privacy Policy

Last updated: June 2026 · App: Latus

Latus is a personal travel-planning app for individual users. This document explains, in plain language, what data the app collects, what it does with it, and what your rights are. We aim to collect as little as possible.

Stored only on your device

Most of Latus's data lives exclusively on your device, inside the app's private storage (SharedPreferences and internal folders). It is not transmitted to us or to any external service. This includes:

What is sent outside — and to whom

1. Google Gemini (AI features)

When you use smart features — AI trip planning and chat, smart translation, journal summaries, place and safety recommendations, and scanning a booking confirmation or boarding pass to import it — Latus sends the relevant content to the Google Gemini API for processing. Depending on the feature this can include the text and trip details you provide, your chat messages, and, when you choose to scan a document, the image or PDF you selected (which may contain personal details such as a passenger name, booking reference, or flight information). The request is routed through our secure Cloud Functions proxy (so the AI key is never shipped inside the app); the response is returned to your device and is not stored on our servers.

Consent first: before your first use of any AI feature, the app shows a disclosure explaining what is sent and to whom, and asks for your explicit permission. Nothing is sent to the AI service before you agree; if you decline, the action is simply not performed and you can agree at any later time. What is never sent to the AI service: your contacts, your photo library (other than a file you explicitly pick for import), your device location, and your account details.

Google's use of data sent to the Gemini API is subject to Google's Privacy Policy, which provides equivalent protection to what is described here.

2. Firebase Authentication + Firestore (shared trips — optional)

The "shared trip" feature lets friends collaborate on planning. Only if you explicitly enable it and sign in with your Google account, the following is sent to Google's Firebase servers:

If you don't sign in with Google and don't enable sharing — your trip content is not synced to the cloud. However, to enable the AI features and prevent abuse, the app creates an anonymous Firebase account, and our proxy server records an anonymous identifier and your IP address to enforce fair-use quotas. These values are kept briefly (typically up to 7 days) and then deleted automatically.

3. Google Maps SDK

When you open a map inside the app, the Google Maps SDK accesses your location (if you granted the permission) to show the blue dot and center the map. Google's use of the SDK is subject to Google's Privacy Policy.

4. Exchange rates (open.er-api.com)

Once a day, the app downloads up-to-date exchange rates from open.er-api.com. The request contains no identifying information about you — it's a plain HTTP request.

5. Offline translation (Google ML Kit)

The first time you open the Translate screen for a specific destination, Google ML Kit language models are downloaded to your device. After download, all translation runs locally without sending text outside.

6. Firebase Analytics & Crashlytics

Latus uses Firebase Analytics (Google Analytics for Firebase) to understand, in aggregate, how the app is used — for example which features are opened — so we can improve it, and Firebase Crashlytics to receive crash and error diagnostics. These collect anonymous, app-internal events and technical device/diagnostic data; they do not collect the content of your trips, documents, or journal. The app does not use an Advertising ID, does not serve ads, and does not sell your data. Google's processing is subject to Google's Privacy Policy.

7. Feedback & bug reports

When you send feedback or report a bug from within the app, we collect the message you wrote together with basic diagnostic details (app version, device model and OS, language, destination and trip dates), plus your anonymous identifier and your email (if you're signed in). This is stored in Firebase Firestore and emailed to our support team to handle your request. We use it only to respond to you and to improve the app.

8. In-app purchases

The app is free and contains no in-app purchases — so we process no payment data at all. If you bought a "paid trip" in an earlier version of the app, the historical entitlement record (which trips were unlocked and the order id, with no payment details) is kept in Firebase Firestore while the account exists and is deleted when you delete it.

System permissions

Latus requests the following permissions, only when actually needed, with an in-app explanation each time:

Your rights

Data retention

Local data — as long as the app is installed. Uninstalling deletes it all. Shared trip data in Firestore — kept as long as at least one member is still part of the trip. Manual deletion is available from within the app. Server-side operational data — AI usage counters and IP addresses are deleted automatically within about 7 days; trip-build jobs within 24 hours; feedback submissions are kept until you ask us to delete them. Historical entitlement records (from versions that offered purchases) are kept while the account exists and are deleted when you delete it.

Legal bases for processing (GDPR)

Where the EU/UK General Data Protection Regulation applies, we rely on: consent (for optional features such as AI processing, trip sharing, and analytics — you choose to use them); performance of our terms (to provide the core app you requested); and our legitimate interests (keeping the service secure and preventing abuse, e.g. rate-limiting and crash diagnostics). You can withdraw consent at any time by stopping use of the relevant feature, signing out, or deleting your data.

Your rights under GDPR

If the GDPR applies to you, you have the right to access, rectify, erase, restrict, and object to processing of your personal data, the right to data portability, and the right to lodge a complaint with your supervisory authority. Because most data lives only on your device, you can exercise many of these rights directly — view and edit your data in the app, export or share it, and wipe it via Settings → "Reset all data". For cloud (shared-trip) data, use Settings → "Delete account & data", or email latus.support@gmail.com and we will respond within one month.

International data transfers

Our processors (Google, and on iOS Apple) operate global infrastructure, so your data may be processed in countries outside your own, including outside the EEA/UK and Israel. These transfers are covered by the providers' data processing terms and Standard Contractual Clauses (SCCs) where required.

Israeli Privacy Protection Law

For users in Israel, we process personal information in line with the Privacy Protection Law, 5741-1981 and its regulations (including Amendment 13). You may contact us at latus.support@gmail.com to access or correct your information or to raise a privacy concern.

California privacy rights (CCPA/CPRA)

We do not sell or "share" (as defined under California law) your personal information, and we do not use it for cross-context behavioural advertising. California residents may request to know, delete, or correct their personal information using the contact details above; we will not discriminate against you for exercising these rights.

Changes to this policy

Updated versions of this document will be published at this URL with a new "last updated" date at the top. Material changes will be announced inside the app before taking effect.

Contact

Questions, deletion requests, or bug reports — please email latus.support@gmail.com.

Related documents