Privacy Policy

Last Updated: August 4, 2026

This privacy policy applies to the Rancang mobile application. We are committed to protecting your personal information and your right to privacy.

1. Who We Are

Rancang is operated by Magebite Technology. For this policy, Magebite Technology is the data controller for personal data we decide how and why to process. You can contact us at 17hieng@gmail.com for privacy questions or requests.

Data Protection Officer: Magebite Technology has designated Eii Chee Hieng as its Data Protection Officer.

Privacy and data-protection requests: 17hieng@gmail.com. The Data Protection Officer handles privacy requests, complaints, retention questions, and other data-protection matters. If we appoint an EU or UK representative, or if one is legally required for Rancang, we will publish the representative contact details in this policy.

2. Information We Collect

We collect or process information only when needed for app features, advertising, or app stability:

3. Device Permissions

Rancang asks for device permissions only when they are needed for features you choose to use:

4. Third-Party Services

We use the following third-party services:

5. Legal Bases for Processing

If EU or UK data protection law applies, we rely on the following legal bases:

6. How We Use Information

7. Data Storage & Retention

Most trip, expense, expense photo, checklist, bill split, settlement, travel document, selected photo, scan, and imported file data is stored locally on your device. We do not have access to local content unless you separately choose to share it with us or use a feature that sends limited information to our backend, such as AI Travel Document Import or currency exchange-rate lookup.

For AI Travel Document Import, original imported PDFs, photos, scans, files, and local file URLs may be stored locally as travel document attachments if you choose to keep them in Rancang, but they are not uploaded for AI parsing. If you tap Detect Details, only extracted text, a local trip identifier, compatibility metadata where received, and limited file metadata are sent to our Firebase backend and then the extracted text is sent to Google Gemini for parsing. Parsed results are returned for your review. Only items you approve are saved locally in Rancang.

Rancang may also store limited local widget and Live Activity snapshots, such as trip or flight countdown and progress information, in the app group container so widgets and Live Activities can display current trip-related information. This is local, on-device app extension storage and is not uploaded automatically by Rancang.

Rancang does not store your full contacts list. If you grant Contacts access, contact names and nicknames are read locally on your device only to suggest friends when adding people to a bill split. Only friend names you choose to add are saved as part of local bill split data. Contacts are not uploaded automatically.

Calendar information accessed by Add to Calendar is processed on your device. Rancang may check events within the relevant trip date range only to avoid adding the same trip more than once. Calendar information accessed by this feature is not transmitted to, stored on, or shared through Rancang's servers. Events created by Rancang are stored in your default calendar and may be synchronized by your calendar provider.

Images, scans, and imported files added to travel documents are copied into app storage and are not uploaded automatically. Local trip, expense, checklist, bill split, settlement, document, photo, scan, and imported file data remains on your device until you delete the item, clear the relevant data, or remove the app, unless it has been backed up through your device backup services.

Local diagnostic logs are capped, rotated, and can be cleared in the app where the feature is available. Bug reports and support emails are retained only as long as reasonably needed for customer support, troubleshooting, legal, security, and business record purposes.

Firebase anonymous account identifiers, AI quota documents, AI usage metrics such as request counts and input, output, thinking, cached, and total token counts, Visa requirement check records, backend request metadata, and Google Cloud logs may be retained to operate features, enforce quotas and subscription limits, monitor costs, prevent abuse, secure services, troubleshoot errors, and comply with legal obligations. The current source configuration contains no Firestore TTL or scheduled deletion for these records.

Current retention status:

You may contact the Data Protection Officer to request review or deletion of backend data Magebite Technology controls. Provider safety logs, immutable security records, and data required for legal, security, or fraud-prevention purposes may be retained only to the extent genuinely necessary.

Google may temporarily retain Gemini API prompts, responses, and related technical information for abuse prevention, safety enforcement, service operation, and legal compliance. If Gemini API project logging is enabled, private request and response logs may be retained for the period configured in Google AI Studio, up to 55 days by default. Google's retention and deletion practices are governed by its Gemini API terms and data logging settings.

Currency conversion sends only the requested date and technical request metadata needed for exchange-rate lookup. Expense names and expense amounts are not sent for currency-rate lookup. The backend may cache exchange-rate data.

Advertising, diagnostic, and ad measurement data processed by Google AdMob is retained by Google according to Google's own policies and settings. We do not control Google's retention periods. We may see aggregated ad reports in Google tools and keep them only as long as needed to understand app performance, advertising performance, and business records.

8. Your Rights & Choices

Depending on where you live, including in the EU or UK, you may have rights to request access, correction, deletion, restriction, portability, or objection to processing of your personal data. Where processing is based on consent, you may withdraw that consent at any time.

Because most Rancang content is stored only on your device, Magebite Technology cannot access, export, or delete that local content for you. You can manage or delete local content directly in the app or by deleting the app from your device. For backend data Magebite Technology controls, email the Data Protection Officer to request access, correction, deletion, restriction, portability where applicable, objection, or review of processing. We will assess each request under applicable law. We may retain only the data genuinely needed for legal obligations, security, fraud prevention, or to establish, exercise, or defend legal claims, and will explain any applicable limitation.

9. Children

Rancang is not directed to children under 13. If you are under the age at which you can legally consent to data processing in your country or region, you should use Rancang only with permission from a parent or guardian. We do not knowingly collect personal data from children on our servers. If you believe a child has provided personal data to us, contact us so we can review and delete it where appropriate.

Personalized advertising or tracking should not be enabled for users who are known to be under the applicable digital consent age.

AI Travel Document Import uses the Google Gemini API and is available only to users aged 18 or older. Users under 18 must not use AI Travel Document Import.

10. International Transfers

Magebite Technology may use providers that process data outside Singapore, the EEA, and the United Kingdom, including Google AdMob, Firebase, Google Cloud, Google Gemini, Apple, and CurrencyAPI. Magebite Technology selects providers and uses legally appropriate contractual, adequacy, or other transfer safeguards where required. The applicable safeguards depend on the provider, service, data, destination, and law governing the transfer.

11. Data Sharing

We do not sell your personal data.

Data may be shared with third-party services only as necessary to provide app functionality, advertising, subscriptions, AI parsing, exchange-rate lookup, security, and app stability. Local travel document attachments, selected photos, expense photos, imported files, and checklist reminder content are not sold or uploaded automatically by Rancang.

If you use AI Travel Document Import and tap Detect Details, extracted booking or travel document text, a local trip identifier, subscription tier, and limited file metadata are sent to Firebase Cloud Functions, and the extracted text is sent to Google Gemini for parsing. Original imported PDFs, photos, scans, files, attachments, and local file URLs are not sent to Google Gemini for this feature. Google may temporarily retain prompts, responses, and related technical information under its Gemini API terms and project logging settings.

Firebase anonymous UID, Firebase Auth tokens, App Check tokens, subscription tier, AI quota metadata, request metadata, and backend logs may be processed by Firebase, Firestore, Google Cloud, and related Google services to operate backend features, enforce quotas, protect services, and troubleshoot issues.

Currency-rate lookup sends the requested date and technical request metadata only to our Firebase backend. The app does not connect directly to an external exchange-rate provider. Our backend may send the requested date to CurrencyAPI and cache returned exchange-rate data. Expense names, expense amounts, trip details, and document contents are not sent for currency-rate lookup.

Calendar information accessed by Add to Calendar is not uploaded to Rancang, stored on Rancang's servers, or shared through Rancang's servers. Events created by Rancang are stored in your default calendar and may be synchronized by your calendar provider according to that provider's privacy policy.

Contacts are read locally on your device and are not uploaded to our servers or shared with third parties. Only names you choose to add are saved as bill split data.

If you choose to send a bug report, your email app sends the report to us, and we use it only for customer support and troubleshooting.

Technical request data may be processed by Firebase and Google Cloud services to provide AI import, currency exchange-rate features, app integrity checks, quota tracking, and backend abuse prevention.

Subscription purchases and entitlement validation are handled through Apple StoreKit and App Store services.

Widget and Live Activity data is stored locally for app extension display and is not uploaded automatically by Rancang.

12. Complaints

If you are in the EU or UK and believe your data protection rights have not been respected, you may contact us first at 17hieng@gmail.com. You also have the right to lodge a complaint with your local data protection supervisory authority.

13. Changes to This Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this page periodically for any changes.

14. Contact Us

If you have any questions, privacy requests, or deletion requests, please contact us at:

Email: 17hieng@gmail.com