codewithtrong.sh
back--packsync
$cat ./packsync/PRIVACY_POLICY.md
privacy_policy.md

Privacy Policy

Effective Date: July 21, 2026

PackSync ("the App," "we," "us," or "our") is developed by Trong Le, doing business as CodeWithTrong ("Developer"). This Privacy Policy explains how the App handles information when you use it on iOS or Android.

1. Account Required

PackSync requires an account to use. You sign in with email and password; there is no guest mode. Every trip is shared only with the people you invite to it, via a shareable invite link.

2. Information the App Stores

The App allows you and your trip members to create and share:

  • Account info: email, display name, and avatar
  • Trips, itineraries, expenses, chat messages, map pins, packing lists, polls, notes, and reservations
  • Trip photos, profile avatars, trip cover photos, and document attachments
  • Live location, only while you opt in to share it for a specific trip

Account and trip data is stored in our hosted backend (Supabase), protected by row-level security so a user can only access data for trips they are a member of. Your authentication tokens are stored encrypted on your device (iOS Keychain / Android Keystore). Your packing list is additionally cached locally on your device so it remains usable offline, and syncs back to the server once you're reconnected. Basic preferences (like theme or language) are stored locally on your device only.

3. Location Sharing

Live location sharing is off by default and only active if you turn it on yourself for a specific trip. While active, your location is sent periodically (roughly every 2 minutes or every 100 meters of movement) and shared only with the members of that trip, never publicly. You can stop sharing at any time.

4. Third-Party Services

PackSync uses the following third-party services:

ServiceWhat's SentPurpose
SupabaseAccount and trip data described aboveBackend database, authentication, and file storage
Photon (Komoot)Free-text place-search queriesGeocoding trip destinations and map place search
Open-MeteoTrip destination coordinatesWeather forecasts on the itinerary screen
Expo Push Notification ServiceDevice push token, notification text, trip/message IDsDelivers push notifications
ntfy.sh or a user-supplied webhookNotification textOptional, only if you configure your own notification target
Apple Maps / Google MapsApproximate map viewportStandard on-device map display; subject to Apple's or Google's own map terms

If you choose to enter your own webhook URL for notifications, that notification content is sent directly to the URL you provide, which is outside our control. We do not use analytics or advertising SDKs, and the App does not track you across other apps or websites.

5. Permissions the App Requests

PermissionPurpose
CameraTake a photo to attach directly to a trip's photo gallery.
Photo LibraryPick photos for a trip gallery, cover photo, or chat attachment.
Location (foreground and background)Used only for opt-in live location sharing with members of a specific trip. If background access is granted, sharing continues while the App is not in focus, with the standard OS indicator shown while active. Off by default; can be stopped at any time.

Your device's permission system may also show requests related to Face ID, microphone, or motion access. These are not features PackSync uses; they are included automatically by bundled third-party components the App relies on. PackSync does not use biometric authentication, does not record audio, and does not track motion. (PackSync does support optional two-factor authentication, but it is authenticator-app/TOTP-based, not device biometrics.)

6. Payments

PackSync does not process payments. The expense-splitting feature calculates who owes whom based on expenses you log; it does not move money, link a bank account, or integrate with any payment provider. Settling up happens outside the App.

7. Data Sharing and Sale

We do not sell your data. We do not share your data with advertisers, data brokers, or any third party outside of the service providers listed above, which process data solely to provide the App's functionality.

8. Security

Trip and account data is protected using authentication and row-level security so only trip members can access it. Authentication tokens are stored encrypted on your device.

9. Changes to This Policy

We may update this Privacy Policy from time to time, for example to reflect new features. We will update the "Effective Date" above when changes are made. Continued use of the App after changes are posted constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy or how the App works, please contact us at:

Email: support@codewithtrong.com
Developer: Trong Le, doing business as CodeWithTrong