Privacy Policy

Last Updated: August 17, 2026

This privacy policy applies to the Rancang mobile application. We are committed to protecting your personal information and your right to privacy.

1. Who We Are

Rancang is operated by Magebite Technology. For this policy, Magebite Technology is the data controller for personal data we decide how and why to process. You can contact us at 17hieng@gmail.com for privacy questions or requests.

Data Protection Officer: Magebite Technology has designated Eii Chee Hieng as its Data Protection Officer.

Privacy and data-protection requests: 17hieng@gmail.com. The Data Protection Officer handles privacy requests, complaints, retention questions, and other data-protection matters. If we appoint an EU or UK representative, or if one is legally required for Rancang, we will publish the representative contact details in this policy.

2. Information We Collect

We collect or process information only when needed for app features, advertising, or app stability:

3. Device Permissions

Rancang asks for device permissions only when they are needed for features you choose to use:

4. Third-Party Services

We use the following third-party services:

5. Legal Bases for Processing

If EU or UK data protection law applies, we rely on the following legal bases:

6. How We Use Information

7. Data Storage & Retention

Most trip, expense, expense photo, checklist, bill split, settlement, travel document, selected photo, scan, and imported file data is stored locally on your device. We do not have access to local content unless you separately choose to share it with us or use a feature that sends limited information to our backend, such as AI Travel Document Import or currency exchange-rate lookup.

For AI Travel Document Import, original imported PDFs, photos, scans, files, and local file URLs may be stored locally as travel document attachments if you choose to keep them in Rancang, but they are not uploaded for AI parsing. If you tap Detect Details, only extracted text, a local trip identifier, compatibility metadata where received, and limited file metadata are sent to our Firebase backend and then the extracted text is sent to Google Gemini for parsing. Parsed results are returned for your review. Only items you approve are saved locally in Rancang.

For AI Travel Suggestions, destination and language requests may be processed by Firebase and the active AI provider. Generated place data and image-attribution metadata may be stored in a shared Firestore cache for up to 365 days. This cache is not linked to your local trip content and is not a personal trip database.

Rancang may also store limited local widget and Live Activity snapshots, such as trip or flight countdown and progress information, in the app group container so widgets and Live Activities can display current trip-related information. This is local, on-device app extension storage and is not uploaded automatically by Rancang.

Rancang does not store your full contacts list. If you grant Contacts access, contact names and nicknames are read locally on your device only to suggest friends when adding people to a bill split. Only friend names you choose to add are saved as part of local bill split data. Contacts are not uploaded automatically.

Calendar information accessed by Add to Calendar is processed on your device. Rancang may check events within the relevant trip date range only to avoid adding the same trip more than once. Calendar information accessed by this feature is not transmitted to, stored on, or shared through Rancang's servers. Events created by Rancang are stored in your default calendar and may be synchronized by your calendar provider.

Images, scans, and imported files added to travel documents are copied into app storage and are not uploaded automatically. Local trip, expense, checklist, bill split, settlement, document, photo, scan, and imported file data remains on your device until you delete the item, clear the relevant data, or remove the app, unless it has been backed up through your device backup services.

Local diagnostic logs are capped, rotated, and can be cleared in the app where the feature is available. Bug reports and support emails are retained only as long as reasonably needed for customer support, troubleshooting, legal, security, and business record purposes.

Firebase anonymous account identifiers, AI quota documents, AI usage metrics such as request counts and input, output, thinking, cached, and total token counts, Visa requirement check records, backend request metadata, and Google Cloud logs may be retained to operate features, enforce quotas and subscription limits, monitor costs, prevent abuse, secure services, troubleshoot errors, and comply with legal obligations. Our retention target for user-linked backend records is described below. Deletion may require a manual request until the relevant automated retention control is active.

Current retention status:

You may contact the Data Protection Officer to request review or deletion of backend data Magebite Technology controls. Provider safety logs, immutable security records, and data required for legal, security, or fraud-prevention purposes may be retained only to the extent genuinely necessary.

Google may temporarily retain Gemini API prompts, responses, and related technical information for abuse prevention, safety enforcement, service operation, and legal compliance. Rancang does not intentionally enable project-level Gemini request/response logging; if it is enabled temporarily, the target is no more than 7 days. Google's retention and deletion practices are governed by its Gemini API terms and data logging settings, which may apply independently of Rancang's settings.

Currency conversion sends only the requested date and technical request metadata needed for exchange-rate lookup. Expense names and expense amounts are not sent for currency-rate lookup. The backend may cache exchange-rate data.

Advertising, diagnostic, and ad measurement data processed by Google AdMob is retained by Google according to Google's own policies and settings. We do not control Google's retention periods. We may see aggregated ad reports in Google tools and keep them only as long as needed to understand app performance, advertising performance, and business records.

8. Your Rights & Choices

Depending on where you live, including in the EU or UK, you may have rights to request access, correction, deletion, restriction, portability, or objection to processing of your personal data. Where processing is based on consent, you may withdraw that consent at any time.

Because most Rancang content is stored only on your device, Magebite Technology cannot access, export, or delete that local content for you. You can manage or delete local content directly in the app or by deleting the app from your device. For backend data Magebite Technology controls, email the Data Protection Officer to request access, correction, deletion, restriction, portability where applicable, objection, or review of processing. We will assess each request under applicable law. We may retain only the data genuinely needed for legal obligations, security, fraud prevention, or to establish, exercise, or defend legal claims, and will explain any applicable limitation.

9. Children

Rancang is not directed to children under 13. If you are under the age at which you can legally consent to data processing in your country or region, you should use Rancang only with permission from a parent or guardian. We do not knowingly collect personal data from children on our servers. If you believe a child has provided personal data to us, contact us so we can review and delete it where appropriate.

Personalized advertising or tracking should not be enabled for users who are known to be under the applicable digital consent age.

AI Travel Document Import and AI Travel Suggestions use backend AI services and are available only to users aged 18 or older. Users under 18 must not use these AI features. Rancang uses a local self-attestation and does not collect a date of birth; this is not a guarantee of a user's age.

10. International Transfers

Magebite Technology may use providers that process data outside Singapore, the EEA, and the United Kingdom, including Google AdMob, Firebase, Google Cloud, Google Gemini, OpenAI where enabled, Apple, Frankfurter, CurrencyAPI, Azure, OpenStreetMap/Overpass, Wikimedia Commons, Google Maps, and Waze. Magebite Technology selects providers and uses legally appropriate contractual, adequacy, or other transfer safeguards where required. The applicable safeguards depend on the provider, service, data, destination, and law governing the transfer.

11. Data Sharing

We do not sell your personal data.

Data may be shared with third-party services only as necessary to provide app functionality, advertising, subscriptions, AI parsing, exchange-rate lookup, security, and app stability. Local travel document attachments, selected photos, expense photos, imported files, and checklist reminder content are not sold or uploaded automatically by Rancang.

If you use AI Travel Document Import and tap Detect Details, extracted booking or travel document text, a local trip identifier, subscription tier, and limited file metadata are sent to Firebase Cloud Functions, and the extracted text is sent to Google Gemini for parsing. Original imported PDFs, photos, scans, files, attachments, and local file URLs are not sent to Google Gemini for this feature. Google may temporarily retain prompts, responses, and related technical information under its Gemini API terms and project logging settings.

Firebase anonymous UID, Firebase Auth tokens, App Check tokens, subscription tier, AI quota metadata, request metadata, and backend logs may be processed by Firebase, Firestore, Google Cloud, and related Google services to operate backend features, enforce quotas, protect services, and troubleshoot issues.

Currency-rate lookup sends the requested date and technical request metadata only to our Firebase backend. The app does not send expense names, expense amounts, trip details, or document contents for currency-rate lookup. The backend may use Frankfurter or CurrencyAPI, and configured iOS releases may use the Azure endpoint protected by Apple App Attest. It may cache returned exchange-rate data.

When you request AI travel suggestions, the destination city, country or region, language, and technical request metadata may be sent to Firebase and the active AI provider. Suggestions may be cached in Firestore and image metadata may be requested from Wikimedia Commons. When you request supplemental place details, selected place names and coordinates may be sent to OpenStreetMap/Overpass. When you choose external navigation, selected names, search terms, and coordinates may be sent to Apple Maps, Google Maps, or Waze.

Calendar information accessed by Add to Calendar is not uploaded to Rancang, stored on Rancang's servers, or shared through Rancang's servers. Events created by Rancang are stored in your default calendar and may be synchronized by your calendar provider according to that provider's privacy policy.

Contacts are read locally on your device and are not uploaded to our servers or shared with third parties. Only names you choose to add are saved as bill split data.

If you choose to send a bug report, your email app sends the report to us, and we use it only for customer support and troubleshooting.

Technical request data may be processed by Firebase and Google Cloud services to provide AI import, currency exchange-rate features, app integrity checks, quota tracking, and backend abuse prevention.

Subscription purchases and entitlement validation are handled through Apple StoreKit and App Store services. A verified transaction JWS and random app-account token may be sent to Firebase for validation; the backend stores parsed entitlement fields rather than the raw JWS.

Widget and Live Activity data is stored locally for app extension display and is not uploaded automatically by Rancang.

12. Complaints

If you are in the EU or UK and believe your data protection rights have not been respected, you may contact us first at 17hieng@gmail.com. You also have the right to lodge a complaint with your local data protection supervisory authority.

13. Changes to This Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this page periodically for any changes.

14. Contact Us

If you have any questions, privacy requests, or deletion requests, please contact us at:

Email: 17hieng@gmail.com