1. Who We Are
Rancang is operated by Magebite Technology. For this policy, Magebite Technology is the
data controller for personal data we decide how and why to process. You can contact us at
17hieng@gmail.com for privacy questions or requests.
We have not appointed a Data Protection Officer. If we appoint an EU or UK representative, or if one is
legally required for Rancang, we will publish the representative contact details in this policy.
2. Information We Collect
We collect or process information only when needed for app features, advertising, or app stability:
-
User-Created Content:
Trip details, expenses, custom categories, currency selections, checklist items,
checklist reminder settings, bill split records, bill split participants, paid/share amounts,
settlement records, travel document records, and Rancang Plus subscription status or entitlement
state where relevant to features you use in the app. Most user-created app content is stored locally
on your device. We do not have access to your local content unless you separately choose to share it
with us or use a feature that sends limited information to our backend, such as AI Travel Document
Import or currency exchange-rate lookup as described below.
-
Contacts:
If you grant Contacts access, Rancang reads contact names and nicknames on your device to suggest
friends when you add people to a bill split. Contacts are read locally on your device. Rancang does
not upload your contacts, share them with third parties, or store your full contacts list. Only names
you choose to add are saved as part of your bill split data. You can deny Contacts access or disable
it anytime in iOS Settings.
-
AI Travel Document Import:
If you choose to import travel details from a PDF, photo, local file, or pasted booking text, Rancang
first reads or extracts text locally on your device using Apple frameworks where available. Original
imported PDFs, photos, scans, or files may be stored locally as travel document attachments if you
choose to keep them in Rancang. Those original PDFs, photos, files, local file URLs, and attachments
are not uploaded for AI parsing. When you tap Detect Details, Rancang sends only the extracted text
and limited metadata to a Firebase Cloud Function named parse_travel_document. The request may include
the extracted text, source type, optional file name, MIME type, file size, and subscription tier. The
backend sends the extracted text to Google Gemini to parse travel details. Parsed results are returned
to you for review, and only items you approve are saved locally in the app.
-
Anonymous Firebase User and AI Quota:
Rancang may silently create or reuse a Firebase anonymous user to support AI import quota tracking.
The anonymous Firebase UID is used to track monthly AI import usage, such as 3 imports per month for
free users and 100 imports per month for Rancang Plus users. Backend quota records may store the UID,
month, usage count, subscription tier, and related request metadata needed to operate and protect the
feature. We store AI usage metrics such as token counts and request counts for quota, billing, abuse
prevention, and service monitoring. Firebase callable requests may automatically include Firebase Auth
and App Check tokens when available.
-
Widget and Live Activity Data:
If you enable widgets or Live Activities, Rancang may store limited local snapshots, such as trip or
flight countdown and progress information, in the app group container so app extensions can display
current trip-related information. This is local, on-device app extension storage and is not uploaded
automatically by Rancang.
-
Travel Document Attachments:
If you choose to take a photo, scan a document, select a photo, or import a file for a travel
document, the selected image, scan, PDF, or file is copied into app storage as a local travel document
attachment. These original attachments are not uploaded automatically, including when AI Travel
Document Import sends extracted text for parsing.
-
Expense Photos:
If you choose to take or attach a photo for an expense, the photo is stored locally in app storage.
Expense photos are not uploaded automatically and are not accessible to us unless you choose to share
them with us, such as through a support request.
-
Bug Reports, Support Requests, and Local Logs:
Rancang may keep local diagnostic logs on your device. Logs are capped, rotated, and intended to be
redacted so they do not intentionally include sensitive trip content. Logs are not uploaded
automatically. If you choose to send a bug report, Rancang creates a local diagnostic report and opens
your email app so you can review and send it. The report may include your written description, app
version, build number, bundle ID, device model, iOS version, locale, and recent redacted local logs.
Your email address is visible to us when you send the email. Bug reports are not sent automatically.
-
Device, Advertising, and Consent Information:
Free users may see Google AdMob ads. Google AdMob, Google's User Messaging Platform, and related
Google services may process device identifiers, advertising identifiers, IP address, approximate
location, app interaction information, diagnostic information, consent choices, and ad performance
information, depending on your device settings, consent choices, and Google's policies. Rancang may
request App Tracking Transparency / IDFA permission for personalized ads where applicable. Rancang Plus disables ads. Ads remain disabled in the app while an active entitlement is available.
3. Device Permissions
Rancang asks for device permissions only when they are needed for features you choose to use:
-
Camera:
Used when you choose to take an expense photo, take a travel document photo, or scan a travel document.
The camera is used only when you choose one of these actions.
-
Selected Photos:
Used for the trip banner photo picker, expense photo attachment, and travel document Select from
Gallery feature. On iOS, Rancang uses PhotosPicker, so the app reads only the photo or photos you
explicitly select and does not require broad photo library access.
-
Selected Files and Documents:
Used when you choose Import File for a travel document. Rancang accesses only the file selected
through the system file picker and copies it into app storage.
-
Contacts:
Used only if you grant access, to read contact names and nicknames locally and suggest friends when
adding people to a bill split. Rancang does not upload your contacts or store your full contacts list.
You can deny or later disable Contacts access in iOS Settings.
-
Calendar Access:
When you choose Add to Calendar, Rancang requests access to your device calendars. Rancang uses this
access to create an all-day event containing your trip name, destination, travel dates, and a Rancang
trip identifier. Rancang may also check events within the relevant date range solely to prevent the
same trip from being added more than once. Calendar information accessed by this feature is processed
on your device and is not transmitted to, stored on, or shared through Rancang's servers. Events
created by Rancang are stored in your default calendar and may be synchronized by your calendar
provider according to that provider's privacy policy. You can revoke Rancang's Calendar access at any
time in Settings > Privacy & Security > Calendars > Rancang. You can remove an exported trip by
deleting the event from Calendar.
-
Notifications:
Used to send local checklist reminder notifications for checklist items that you select or set up
in the app. You can manage notification permission in your device settings.
-
App Tracking Transparency / IDFA:
Used on iOS to request permission before accessing the advertising identifier or allowing tracking
across apps and websites for personalized ads and ad measurement. If you deny tracking permission,
ads may still be shown without cross-app tracking.
4. Third-Party Services
We use the following third-party services:
-
Google AdMob and User Messaging Platform:
Used to display advertisements to free users, request and manage advertising consent where required,
and measure ad performance. AdMob may process device and advertising information to provide,
personalize, limit, and measure ads, depending on your consent choices and device settings. If you do
not consent to personalized ads or tracking, Rancang may request non-personalized or limited ads where
allowed, or may not request ads if consent is required and has not been granted. Rancang Plus disables ads while an active subscription entitlement is available. Google's handling of this data is governed
by Google's privacy policies and advertising terms.
-
Firebase Auth, Cloud Functions, App Check, Firestore, and Google Cloud:
Rancang uses Firebase anonymous authentication to create or reuse an anonymous user for AI import
quota tracking. Rancang uses Firebase Cloud Functions for backend features such as AI travel document
parsing and exchange-rate lookup, Firebase App Check to help protect backend endpoints, and Firestore
or Google Cloud logging to store limited backend metadata such as quota counters, request metadata,
operational logs, and abuse-prevention information. Firebase callable requests may include Firebase
Auth and App Check tokens automatically when available.
-
Google Gemini API:
When you tap Detect Details for AI Travel Document Import, the backend sends extracted travel document
text to Google Gemini to parse booking or travel details. Original imported PDFs, photos, scans, files,
attachments, and local file URLs are not sent to Google Gemini for this feature.
-
FreeCurrencyAPI and Exchange-Rate Backend:
Rancang retrieves exchange-rate data through our backend, which may call FreeCurrencyAPI or another
currency provider. For currency-rate lookup, Rancang sends the requested date needed for the rate
request. Expense names and expense amounts are not sent for currency-rate lookup. The backend may
cache exchange-rate data to improve performance and reduce repeated provider requests.
-
Apple Maps and Geocoding Services:
When the app displays maps or resolves a trip or expense location, Apple services may process the
location text you entered, such as a city or place name, to return map results. Rancang does not
request your current device location for these map features.
-
Apple App Store / StoreKit:
Rancang uses Apple StoreKit and the App Store to offer, purchase, restore, and validate Rancang Plus
subscriptions. Apple may process purchase, subscription, transaction, Apple ID, device, and
payment-related information according to Apple's own privacy policy and App Store terms. Rancang
receives only the subscription, product, transaction, and entitlement information needed to unlock
Rancang Plus features, hide ads for subscribers, and restore purchases.
5. Legal Bases for Processing
If EU or UK data protection law applies, we rely on the following legal bases:
-
Performance of a contract:
To provide app features you request, such as saving trips, expenses, checklists, travel documents, AI import parsing, subscription entitlements, and exchange-rate lookup.
-
Consent:
For permissions such as notifications, camera access, selected photos, selected files, contacts, calendar access, and tracking
or personalized advertising where consent is required. You can withdraw or change advertising consent
through Rancang's in-app Privacy Choices where available, and you can manage device permissions through
your device settings.
-
Legitimate interests:
To keep the app functional, improve reliability, prevent abuse, enforce AI import quotas, protect backend services, cache exchange-rate data, and show non-personalized ads where allowed by law and your settings.
-
Legal obligation:
To comply with applicable laws, regulatory requests, or enforceable legal processes if they apply.
6. How We Use Information
- Provide and maintain app functionality
- Store and display trip, checklist, and travel document information you add in the app
- Parse extracted travel document text when you choose AI Travel Document Import
- Store and display bill split and settlement information you add in the app
- Suggest friend names from local contacts when you add people to a bill split, if you grant Contacts access
- Schedule local checklist reminder notifications when you choose to set reminders
- Display trip or flight-related information in widgets and Live Activities when enabled
- Create calendar events for trips when you choose Add to Calendar
- Manage Rancang Plus purchases, subscription status, feature unlocks, and purchase restoration
- Create or reuse an anonymous Firebase user to track AI import quotas and protect backend services
- Retrieve and cache currency exchange-rate data for requested dates
- Improve app performance and user experience
- Respond to bug reports and support requests
- Diagnose app errors using user-submitted diagnostic reports and recent redacted local logs you choose to send
- Display advertisements that support the app
- Measure ad performance and prevent ad-related fraud or abuse
7. Data Storage & Retention
Most trip, expense, expense photo, checklist, bill split, settlement, travel document, selected photo, scan,
and imported file data is stored locally on your device. We do not have access to local
content unless you separately choose to share it with us or use a feature that sends limited information to
our backend, such as AI Travel Document Import or currency exchange-rate lookup.
For AI Travel Document Import, original imported PDFs, photos, scans, files, and local file URLs may be
stored locally as travel document attachments if you choose to keep them in Rancang, but they are not
uploaded for AI parsing. If you tap Detect Details, only extracted text and limited file metadata are sent
to our Firebase backend and then the extracted text is sent to Google Gemini for parsing. Parsed results
are returned for your review. Only items you approve are saved locally in Rancang.
Rancang may also store limited local widget and Live Activity snapshots, such as trip or flight countdown
and progress information, in the app group container so widgets and Live Activities can display current
trip-related information. This is local, on-device app extension storage and is not uploaded automatically
by Rancang.
Rancang does not store your full contacts list. If you grant Contacts access, contact names and nicknames
are read locally on your device only to suggest friends when adding people to a bill split. Only friend
names you choose to add are saved as part of local bill split data. Contacts are not uploaded automatically.
Calendar information accessed by Add to Calendar is processed on your device. Rancang may check events
within the relevant trip date range only to avoid adding the same trip more than once. Calendar information
accessed by this feature is not transmitted to, stored on, or shared through Rancang's servers. Events
created by Rancang are stored in your default calendar and may be synchronized by your calendar provider.
Images, scans, and imported files added to travel documents are copied into app storage and are not
uploaded automatically. Local trip, expense, checklist, bill split, settlement, document, photo, scan, and
imported file data remains on your device until you delete the item, clear the relevant data, or remove the
app, unless it has been backed up through your device backup services.
Local diagnostic logs are capped, rotated, and can be cleared in the app where the feature is available.
Bug reports and support emails are retained only as long as reasonably needed for customer support,
troubleshooting, legal, security, and business record purposes.
Firebase anonymous account identifiers, AI quota documents, AI usage metrics such as token counts and
request counts, backend request metadata, App Check or Auth token metadata, Firestore records, and Google
Cloud logs may be retained as needed to operate AI import, enforce monthly quotas, support billing, prevent
abuse, secure backend services, troubleshoot errors, and comply with legal
obligations. We do not promise a fixed deletion timing for backend logs or quota records unless and until a
specific retention schedule is implemented. You may contact us to request deletion or review of personal
data we control.
Currency conversion sends only the requested date and technical request metadata needed for exchange-rate
lookup. Expense names and expense amounts are not sent for currency-rate lookup. The backend may cache
exchange-rate data.
Advertising, diagnostic, and ad measurement data processed by Google AdMob is retained by Google according
to Google's own policies and settings. We do not control Google's retention periods. We may see aggregated
ad reports in Google tools and keep them only as long as needed to understand app performance, advertising
performance, and business records.
8. Your Rights & Choices
Depending on where you live, including in the EU or UK, you may have rights to request access,
correction, deletion, restriction, portability, or objection to processing of your personal data. Where
processing is based on consent, you may withdraw that consent at any time.
- Access and manage your trip, checklist, and travel document data within the app
- Delete local app data by removing the app or deleting items within the app where available
- Review AI-imported travel details before approving and saving them locally
- Clear local diagnostic logs in the app where this control is available
- Choose whether to grant camera, selected photo, file picker, Contacts, and notification permissions
- Deny Contacts access or disable it later in iOS Settings
- Review or change advertising consent through Rancang's in-app Privacy Choices where available
- Opt out of personalized advertising through your device settings
- Manage tracking permissions through Apple's App Tracking Transparency settings
- Manage or cancel Rancang Plus subscriptions through your Apple ID or App Store subscription settings
- Disable widgets or Live Activities through iOS settings or by removing them from your device screens
- Contact us at 17hieng@gmail.com to make a privacy or deletion request, including requests related to Firebase anonymous UID quota records or support emails
Because most Rancang content is stored only on your device, we may not be able to access, export, or delete
that local content for you. You can manage or delete local content directly in the app or by deleting the
app from your device. For backend data that we control, such as support emails or Firebase anonymous quota
records, you can contact us and we will review the request subject to security, fraud-prevention, legal,
and operational needs.
9. Children
Rancang is not directed to children under 13. If you are under the age at which you can legally consent to
data processing in your country or region, you should use Rancang only with permission from a parent or
guardian. We do not knowingly collect personal data from children on our servers. If you believe a child
has provided personal data to us, contact us so we can review and delete it where appropriate.
Personalized advertising or tracking should not be enabled for users who are known to be under the
applicable digital consent age.
10. International Transfers
Google AdMob, Firebase, Google Cloud, Google Gemini, Apple, FreeCurrencyAPI, and other providers may
process data in countries outside your country or region, including outside the European Economic Area.
Where required, these providers are responsible for using appropriate transfer safeguards for data they
process through their services.
11. Data Sharing
We do not sell your personal data.
Data may be shared with third-party services only as necessary to provide app functionality, advertising,
subscriptions, AI parsing, exchange-rate lookup, security, and app stability. Local travel document
attachments, selected photos, expense photos, imported files, and checklist reminder content are not sold
or uploaded automatically by Rancang.
If you use AI Travel Document Import and tap Detect Details, extracted booking or travel document text and
limited file metadata are sent to Firebase Cloud Functions, and the extracted text is sent to Google Gemini
for parsing. Original imported PDFs, photos, scans, files, attachments, and local file URLs are not sent to
Google Gemini for this feature.
Firebase anonymous UID, Firebase Auth tokens, App Check tokens, subscription tier, AI quota metadata,
request metadata, and backend logs may be processed by Firebase, Firestore, Google Cloud, and related
Google services to operate backend features, enforce quotas, protect services, and troubleshoot issues.
Currency-rate lookup sends the requested date and technical request metadata to our backend. The backend
may call FreeCurrencyAPI or another exchange-rate provider and may cache exchange-rate data. Expense names
and expense amounts are not sent for currency-rate lookup.
Calendar information accessed by Add to Calendar is not uploaded to Rancang, stored on Rancang's servers,
or shared through Rancang's servers. Events created by Rancang are stored in your default calendar and may
be synchronized by your calendar provider according to that provider's privacy policy.
Contacts are read locally on your device and are not uploaded to our servers or shared with third parties.
Only names you choose to add are saved as bill split data.
If you choose to send a bug report, your email app sends the report to us, and we use it only for customer
support and troubleshooting.
Technical request data may be processed by Firebase and Google Cloud services to provide AI import,
currency exchange-rate features, app integrity checks, quota tracking, and backend abuse prevention.
Subscription purchases and entitlement validation are handled through Apple StoreKit and App Store
services.
Widget and Live Activity data is stored locally for app extension display and is not uploaded
automatically by Rancang.
12. Complaints
If you are in the EU or UK and believe your data protection rights have not been respected, you may contact
us first at 17hieng@gmail.com. You also have the right to lodge a
complaint with your local data protection supervisory authority.
13. Changes to This Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new
Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this page
periodically for any changes.