Privacy & Data Usage Policy

Last Updated: January 1, 2025

1. Introduction

This Privacy & Data Usage Policy ("Policy") describes how Expedition America Travel Co. LLC, DBA City Discoverer ("Company", "we", "us", or "our") collects, uses, and protects your information when you use the City Discoverer mobile application ("App"). We are committed to protecting your privacy and handling your data transparently.

2. Information We Collect

We collect minimal data necessary to provide our service: a) Device Information - A unique device identifier (fingerprint) generated locally on your device for rate limiting purposes - Device type and operating system version for compatibility b) Usage Data - Number of itineraries generated (for free tier limits) - Destination searches and preferences you provide - Feedback and ratings you voluntarily submit c) Itinerary Data - Destinations, dates, and personalization text you enter - Generated itineraries are stored locally on your device d) Subscription Data - Subscription tier and expiration information managed through Apple or Google Play

3. Information We Do NOT Collect

We want to be clear about what we do not collect: - We do not collect your real name, email address, or phone number (unless you contact support) - We do not collect your location data or GPS coordinates - We do not access your contacts, camera, photos, or microphone - We do not collect financial or payment information (payments are handled by Apple and Google Play) - We do not create user accounts or require registration - We do not use cookies or web tracking technologies - We do not collect data from children under 13

4. How We Use Your Information

We use the information we collect for: - Generating personalized travel itineraries based on your input - Enforcing rate limits to ensure fair usage of our service - Verifying subscription status for premium features - Improving our AI models and service quality (aggregated, anonymous data only) - Responding to support inquiries - Detecting and preventing abuse or fraud

5. Data Storage and Security

- Itineraries are stored locally on your device using secure storage mechanisms - Device fingerprints are generated and stored locally; they are only transmitted to our servers for rate limiting - We use industry-standard encryption for data in transit (HTTPS/TLS) - Server-side data is stored on secure, encrypted infrastructure - We retain server-side usage data for no longer than 90 days - We do not sell, rent, or trade your data to third parties

6. Third-Party Services

We use the following third-party services: - OpenAI: Our AI itinerary generation is powered by OpenAI's language models. Your destination and personalization text is sent to OpenAI's API for processing. OpenAI's privacy policy applies to this data processing. OpenAI does not use API data for model training. - Apple App Store / Google Play Store: For app distribution and subscription management. Their respective privacy policies govern their data handling. - RevenueCat: For subscription management across platforms. RevenueCat's privacy policy applies to subscription-related data processing. We do not share your data with advertising networks, analytics platforms, or data brokers.

7. Data Retention

- Local data: Stored on your device until you delete it or uninstall the App - Server-side usage records: Retained for up to 90 days, then automatically purged - Feedback submissions: Retained for service improvement purposes, anonymized after 12 months - Shared itineraries: Available for 30 days via share links, then automatically deleted You can delete all local data at any time through the App's Settings by using the Delete Account option.

8. Your Rights

You have the right to: - Access: View all data stored locally on your device - Deletion: Delete all your data through the App's Settings - Portability: Share or export your itineraries - Opt-out: Stop using the App at any time - Inquire: Contact us about what data we hold about you For residents of California (CCPA), the European Union (GDPR), or other jurisdictions with specific data protection laws, additional rights may apply. Contact us at hello@citydiscoverer.ai for assistance.

9. Children's Privacy

City Discoverer is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected data from a child under 13, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us immediately.

10. International Data Transfers

Our servers are located in the United States. If you use the App from outside the United States, your data may be transferred to and processed in the United States. By using the App, you consent to this transfer. We ensure that appropriate safeguards are in place for any international data transfers.

11. Changes to This Policy

We may update this Policy from time to time. We will notify you of material changes through the App or by other reasonable means. Your continued use of the App after changes are posted constitutes your acceptance of the revised Policy.

12. Contact Us

For questions or concerns about this Policy or our data practices: Expedition America Travel Co. LLC DBA City Discoverer 609 Frederick St, Cumberland, MD 21502 Email: hello@citydiscoverer.ai