1. Who We Are
Rancang is operated by Magebite Technology. For this policy, Magebite Technology is the
data controller for personal data we decide how and why to process. You can contact us at
17hieng@gmail.com for privacy questions or requests.
Data Protection Officer:
Magebite Technology has designated Eii Chee Hieng as its Data Protection Officer.
Privacy and data-protection requests:
17hieng@gmail.com. The Data Protection Officer handles privacy
requests, complaints, retention questions, and other data-protection matters. If we appoint an EU or UK
representative, or if one is legally required for Rancang, we will publish the representative contact
details in this policy.
2. Information We Collect
We collect or process information only when needed for app features, advertising, or app stability:
-
User-Created Content:
Trip details, expenses, custom categories, currency selections, checklist items,
checklist reminder settings, bill split records, bill split participants, paid/share amounts,
settlement records, travel document records, and Rancang Plus subscription status or entitlement
state where relevant to features you use in the app. Most user-created app content is stored locally
on your device. We do not have access to your local content unless you separately choose to share it
with us or use a feature that sends limited information to our backend, such as AI Travel Document
Import or currency exchange-rate lookup as described below.
-
Contacts:
If you grant Contacts access, Rancang reads contact names and nicknames on your device to suggest
friends when you add people to a bill split. Contacts are read locally on your device. Rancang does
not upload your contacts, share them with third parties, or store your full contacts list. Only names
you choose to add are saved as part of your bill split data. You can deny Contacts access or disable
it anytime in iOS Settings.
-
AI Travel Document Import:
If you choose to import travel details from a PDF, photo, local file, or pasted booking text, Rancang
first reads or extracts text locally on your device using Apple frameworks where available. Original
imported PDFs, photos, scans, or files may be stored locally as travel document attachments if you
choose to keep them in Rancang. Those original PDFs, photos, files, local file URLs, and attachments
are not uploaded for AI parsing. When you tap Detect Details, Rancang sends only the extracted text
and limited metadata to a Firebase Cloud Function named parse_travel_document. The request may include
the extracted text, a local trip identifier, source type, optional file name, MIME type, file size, subscription
tier, and compatibility metadata such as protocol version, app version, build number, or platform where
received. The local trip identifier is a randomly generated identifier for the trip, not your Firebase
account identifier. The backend sends the extracted text to Google Gemini to parse travel
details. Parsed results are returned to you for review, and only items you approve are saved locally in
the app. AI Travel Document Import is available only to users aged 18 or older.
-
Anonymous Firebase User and AI Quota:
Rancang may silently create or reuse a Firebase anonymous user to support AI feature usage and quota
tracking. The anonymous Firebase UID is used to track monthly AI import usage, such as 3 imports per month for
free users and 100 imports per month for Rancang Plus users. Backend quota records may store the UID,
month, usage count, subscription tier, and related request metadata needed to operate and protect the
feature. We store AI usage metrics such as token counts and request counts for quota, billing, abuse
prevention, and service monitoring. Firebase callable requests may automatically include Firebase Auth
and App Check tokens when available.
-
AI Travel Suggestions:
When you view destination suggestions, Rancang may send the destination city, country or region,
requested app language, a local Firebase anonymous UID, and compatibility metadata to a Firebase
Cloud Function. The backend may send the destination and language to its configured AI provider,
such as Google Gemini or OpenAI, to generate suggested places. Results may be stored in a shared
Firestore cache for up to 365 days and can include place names, descriptions, addresses, coordinates,
and image-attribution metadata. This feature is available only to users aged 18 or older.
-
Backend Service-Usage and Operational Data:
Rancang may associate limited backend service-usage and operational data with a Firebase anonymous user
identifier. This may include AI import request counts; safe lifecycle stages and error codes; input,
output, thinking, cached, and total token usage; AI quota and subscription-period usage; Visa and entry
requirement request counts and safe route/status metadata; protocol or app metadata where received; source
type and MIME type where received; request timestamps, request duration, and technical diagnostics; and
abuse-prevention and service-security metadata. This information is used to provide and operate app
features, enforce AI quotas and subscription limits, detect abuse, protect backend services, troubleshoot
reliability, perform aggregate product and service analysis, and monitor billing or AI cost where
applicable. It is not sold and is not used for advertising unless separately disclosed in this policy.
The current backend does not maintain a separate per-user AI success/failure counter; safe success and
failure stages may appear in operational logs.
-
Widget and Live Activity Data:
If you enable widgets or Live Activities, Rancang may store limited local snapshots, such as trip or
flight countdown and progress information, in the app group container so app extensions can display
current trip-related information. This is local, on-device app extension storage and is not uploaded
automatically by Rancang.
-
Travel Document Attachments:
If you choose to take a photo, scan a document, select a photo, or import a file for a travel
document, the selected image, scan, PDF, or file is copied into app storage as a local travel document
attachment. These original attachments are not uploaded automatically, including when AI Travel
Document Import sends extracted text for parsing.
-
Expense Photos:
If you choose to take or attach a photo for an expense, the photo is stored locally in app storage.
Expense photos are not uploaded automatically and are not accessible to us unless you choose to share
them with us, such as through a support request.
-
Bug Reports, Support Requests, and Local Logs:
Rancang may keep local diagnostic logs on your device. Logs are capped, rotated, and are not uploaded
automatically. If you choose to send a bug report, Rancang creates a local diagnostic report and opens
your email app so you can review and send it. The report may include your written description, app
version, build number, bundle ID, device model, iOS version, locale, and recent redacted local logs.
Your email address is visible to us when you send the email. Bug reports are not sent automatically.
Backend production telemetry and Cloud Logging use allowlisted operational fields and must not
intentionally contain raw OCR text, travel-document contents, AI prompts, AI responses, original PDFs,
photos or scans, authentication tokens, App Check tokens, API keys, full request payloads, or filenames
containing personal information. Local logs are intended to follow the same minimization rule; do not
include confidential information in a support description.
-
Device, Advertising, and Consent Information:
Free users may see Google AdMob ads. Google AdMob, Google's User Messaging Platform, and related
Google services may process device identifiers, advertising identifiers, IP address, approximate
location, app interaction information, diagnostic information, consent choices, and ad performance
information, depending on your device settings, consent choices, and Google's policies. Rancang may
request App Tracking Transparency / IDFA permission for personalized ads where applicable. Rancang Plus disables ads. Ads remain disabled in the app while an active entitlement is available.
3. Device Permissions
Rancang asks for device permissions only when they are needed for features you choose to use:
-
Camera:
Used when you choose to take an expense photo, take a travel document photo, or scan a travel document.
The camera is used only when you choose one of these actions.
-
Selected Photos:
Used for the trip banner photo picker, expense photo attachment, and travel document Select from
Gallery feature. On iOS, Rancang uses PhotosPicker, so the app reads only the photo or photos you
explicitly select and does not require broad photo library access.
-
Selected Files and Documents:
Used when you choose Import File for a travel document. Rancang accesses only the file selected
through the system file picker and copies it into app storage.
-
Contacts:
Used only if you grant access, to read contact names and nicknames locally and suggest friends when
adding people to a bill split. Rancang does not upload your contacts or store your full contacts list.
You can deny or later disable Contacts access in iOS Settings.
-
Calendar Access:
When you choose Add to Calendar, Rancang requests access to your device calendars. Rancang uses this
access to create an all-day event containing your trip name, destination, travel dates, and a Rancang
trip identifier. Rancang may also check events within the relevant date range solely to prevent the
same trip from being added more than once. Calendar information accessed by this feature is processed
on your device and is not transmitted to, stored on, or shared through Rancang's servers. Events
created by Rancang are stored in your default calendar and may be synchronized by your calendar
provider according to that provider's privacy policy. You can revoke Rancang's Calendar access at any
time in Settings > Privacy & Security > Calendars > Rancang. You can remove an exported trip by
deleting the event from Calendar.
-
Notifications:
Used to send local checklist, trip, flight, and travel-document reminders that you select or enable in
the app. Notification content may include relevant trip, flight, checklist, or travel-document
information. You can manage notification permission in your device settings.
-
App Tracking Transparency / IDFA:
Used on iOS to request permission before accessing the advertising identifier or allowing tracking
across apps and websites for personalized ads and ad measurement. If you deny tracking permission,
ads may still be shown without cross-app tracking.
4. Third-Party Services
We use the following third-party services:
-
Google AdMob and User Messaging Platform:
Used to display advertisements to free users, request and manage advertising consent where required,
and measure ad performance. AdMob may process device and advertising information to provide,
personalize, limit, and measure ads, depending on your consent choices and device settings. If you do
not consent to personalized ads or tracking, Rancang may request non-personalized or limited ads where
allowed, or may not request ads if consent is required and has not been granted. Rancang Plus disables ads while an active subscription entitlement is available. Google's handling of this data is governed
by Google's privacy policies and advertising terms.
-
Firebase Authentication:
Rancang silently creates or reuses an anonymous Firebase user. The anonymous Firebase UID is used to
associate AI quota, token-usage summaries, and Visa requirement check history with the same app
installation or user context. Rancang does not use Firebase Authentication for a user-facing account
login in the current iOS implementation.
-
Firebase App Check:
Firebase App Check helps protect callable endpoints. Firebase may process app-integrity signals and App
Check tokens that accompany callable requests. Rancang does not intentionally store App Check tokens in
application logs.
-
Firebase Cloud Functions:
Rancang uses callable Cloud Functions for AI travel-document parsing, AI travel suggestions,
exchange-rate lookup, Visa and entry-requirement lookup, and related backend operations. Depending on
the feature, requests may include extracted text, a local trip identifier, destination city and country,
requested language, source and file metadata, a requested currency date, Visa route and purpose data,
subscription tier, protocol metadata, and Firebase Auth or App Check context.
-
Firestore:
Firestore stores limited backend records such as AI quota and token-usage summaries, Visa requirement
check history, cached exchange rates, and operational configuration. Firestore records do not contain
the original travel-document PDF, photo, scan, or raw OCR attachment from AI Import.
-
Google Cloud Logging:
Google Cloud Logging receives safe operational logs for backend monitoring and troubleshooting, including
request stages, error codes, durations, source type, MIME type, text length, token metrics, and service
metadata. Rancang does not intentionally log raw OCR text, travel-document contents, AI prompts or
responses, original files, authentication or App Check tokens, API keys, or full request payloads.
-
Google Gemini API:
When you tap Detect Details for AI Travel Document Import, the backend sends extracted travel document
text to Google Gemini to parse booking or travel details. For AI Travel Suggestions, the backend may
send destination and language requests to Google Gemini when that provider is active. Original imported
PDFs, photos, scans, files, attachments, and local file URLs are not sent to Google Gemini for document
parsing. Google may temporarily
log prompts, responses, and related technical information for abuse prevention, safety enforcement,
service operation, and legal compliance under the Gemini API terms. The backend does not intentionally
enable project-level Gemini request and response logging. If project logging is enabled temporarily for
troubleshooting, it is configured for the shortest practical period and no longer than 7 days. Google
may independently retain prompts, responses, and technical information for abuse prevention, safety
enforcement, service operation, and legal compliance; Google's retention depends on the applicable
Gemini API service and terms.
-
OpenAI API where enabled:
The backend may use an OpenAI model for AI Travel Suggestions if the active server rollout selects one.
In that case, the destination, country or region, requested language, and prompt needed to generate
suggestions are processed by OpenAI under its applicable API terms and privacy documentation.
-
Exchange-Rate and Transit Providers:
Rancang retrieves exchange-rate data through our Firebase backend. The backend may use Frankfurter or
CurrencyAPI and cache the returned rate data. Configured iOS releases may also use an Azure-hosted
Rancang endpoint for currency and transit estimates. The Azure endpoints use Apple App Attest
attestation or assertion data to help protect the service. Currency requests contain the requested
date and technical request data, not expense names, expense amounts, trip details, or document contents.
Transit requests may contain selected route coordinates, departure time, travel mode, and locale.
-
AI Travel Suggestions and Wikimedia Commons:
The travel-suggestion backend may use Google Gemini or OpenAI according to the active server rollout.
It may query the Wikimedia Commons API and Wikimedia image hosts using place and destination terms to
find public image metadata. Returned image URLs, author, license, and attribution information may be
cached with the suggestion. Wikimedia and image-host processing is governed by those providers' own
terms and privacy policies.
-
OpenStreetMap and Overpass:
When Rancang looks up supplemental place details, it may send a selected place name and selected or
resolved coordinates to the Overpass API at OpenStreetMap. Results may include opening hours, phone,
website, and image or Wikimedia Commons tags. Rancang does not request your current device location for
this feature. OpenStreetMap, Overpass, and any image host involved process requests under their own
policies.
-
Visa and Entry Requirements Backend:
Rancang uses a Firebase Cloud Function backed by Firestore-curated travel guidance. The backend may
receive passport country, destination country, travel purpose, optional departure and return dates, and
locale. It stores a check record associated with the Firebase anonymous UID containing route, purpose,
result status, and check timestamps. It is not an external Visa API and does not require passport
numbers, traveller names, or document scans for this feature.
-
Apple Maps and Geocoding Services:
When the app displays maps, searches for a place, or resolves a trip or expense location, Apple
services may process place names, addresses, search queries, and selected or resolved map coordinates
to return map and geocoding results. Rancang does not request your current device location for these
map features.
-
External Navigation Apps:
When you choose to open a place or route in Apple Maps, Google Maps, or Waze, Rancang passes the
selected place or route names, search terms, and/or coordinates to the app or URL you selected. The
selected provider may process that information under its own privacy policy. Rancang does not send
these navigation requests automatically.
-
Apple App Store / StoreKit:
Rancang uses Apple StoreKit and the App Store to offer, purchase, restore, and validate Rancang Plus
subscriptions. Apple may process purchase, subscription, transaction, Apple ID, device, and
payment-related information according to Apple's own privacy policy and App Store terms. Rancang
receives only the subscription, product, transaction, and entitlement information needed to unlock
Rancang Plus features, hide ads for subscribers, and restore purchases. When server validation is
needed, Rancang sends a verified StoreKit transaction JWS and a random app-account token to Firebase.
The backend verifies the JWS and stores parsed entitlement and transaction fields; it does not retain the
raw JWS after validation.
5. Legal Bases for Processing
If EU or UK data protection law applies, we rely on the following legal bases:
-
Performance of a contract:
To provide app features you request, such as saving trips, expenses, checklists, travel documents, AI
travel suggestions, AI import parsing, subscription entitlements, and exchange-rate lookup.
-
Consent:
For permissions such as notifications, camera access, selected photos, selected files, contacts, calendar access, and tracking
or personalized advertising where consent is required. You can withdraw or change advertising consent
through Rancang's in-app Privacy Choices where available, and you can manage device permissions through
your device settings.
-
Legitimate interests:
To keep the app functional, improve reliability, prevent abuse, enforce AI import quotas, protect backend services, cache exchange-rate data, and show non-personalized ads where allowed by law and your settings.
-
Legal obligation:
To comply with applicable laws, regulatory requests, or enforceable legal processes if they apply.
6. How We Use Information
- Provide and maintain app functionality
- Store and display trip, checklist, and travel document information you add in the app
- Parse extracted travel document text when you choose AI Travel Document Import
- Store and display bill split and settlement information you add in the app
- Suggest friend names from local contacts when you add people to a bill split, if you grant Contacts access
- Schedule local checklist reminder notifications when you choose to set reminders
- Display trip or flight-related information in widgets and Live Activities when enabled
- Create calendar events for trips when you choose Add to Calendar
- Manage Rancang Plus purchases, subscription status, feature unlocks, and purchase restoration
- Create or reuse an anonymous Firebase user to track AI import quotas and protect backend services
- Operate, secure, and analyze backend service usage, AI quota usage, token metrics, and reliability signals
- Count and review Visa and entry-requirement checks using safe route and result metadata
- Retrieve and cache currency exchange-rate data for requested dates
- Generate destination suggestions and related place-image metadata when you request travel suggestions
- Improve app performance and user experience
- Respond to bug reports and support requests
- Diagnose app errors using user-submitted diagnostic reports and recent redacted local logs you choose to send
- Display advertisements that support the app
- Measure ad performance and prevent ad-related fraud or abuse
7. Data Storage & Retention
Most trip, expense, expense photo, checklist, bill split, settlement, travel document, selected photo, scan,
and imported file data is stored locally on your device. We do not have access to local
content unless you separately choose to share it with us or use a feature that sends limited information to
our backend, such as AI Travel Document Import or currency exchange-rate lookup.
For AI Travel Document Import, original imported PDFs, photos, scans, files, and local file URLs may be
stored locally as travel document attachments if you choose to keep them in Rancang, but they are not
uploaded for AI parsing. If you tap Detect Details, only extracted text, a local trip identifier, compatibility metadata where received, and
limited file metadata are sent to our Firebase backend and then the extracted text is sent to Google Gemini
for parsing. Parsed results are returned for your review. Only items you approve are saved locally in
Rancang.
For AI Travel Suggestions, destination and language requests may be processed by Firebase and the active AI
provider. Generated place data and image-attribution metadata may be stored in a shared Firestore cache for
up to 365 days. This cache is not linked to your local trip content and is not a personal trip database.
Rancang may also store limited local widget and Live Activity snapshots, such as trip or flight countdown
and progress information, in the app group container so widgets and Live Activities can display current
trip-related information. This is local, on-device app extension storage and is not uploaded automatically
by Rancang.
Rancang does not store your full contacts list. If you grant Contacts access, contact names and nicknames
are read locally on your device only to suggest friends when adding people to a bill split. Only friend
names you choose to add are saved as part of local bill split data. Contacts are not uploaded automatically.
Calendar information accessed by Add to Calendar is processed on your device. Rancang may check events
within the relevant trip date range only to avoid adding the same trip more than once. Calendar information
accessed by this feature is not transmitted to, stored on, or shared through Rancang's servers. Events
created by Rancang are stored in your default calendar and may be synchronized by your calendar provider.
Images, scans, and imported files added to travel documents are copied into app storage and are not
uploaded automatically. Local trip, expense, checklist, bill split, settlement, document, photo, scan, and
imported file data remains on your device until you delete the item, clear the relevant data, or remove the
app, unless it has been backed up through your device backup services.
Local diagnostic logs are capped, rotated, and can be cleared in the app where the feature is available.
Bug reports and support emails are retained only as long as reasonably needed for customer support,
troubleshooting, legal, security, and business record purposes.
Firebase anonymous account identifiers, AI quota documents, AI usage metrics such as request counts and
input, output, thinking, cached, and total token counts, Visa requirement check records, backend request
metadata, and Google Cloud logs may be retained to operate features, enforce quotas and subscription limits,
monitor costs, prevent abuse, secure services, troubleshoot errors, and comply with legal obligations. Our
retention target for user-linked backend records is described below. Deletion may require a manual request
until the relevant automated retention control is active.
Current retention status:
- User AI usage summaries and quota records: Our target is to retain per-user Firestore records for up to 395 days from their latest update for quota, billing, abuse prevention, and service monitoring, then delete them through our retention process.
- Visa requirement checks: Our target is to retain per-user check records for up to 395 days from their latest update, then delete them through our retention process.
- Travel suggestions: Shared destination suggestion and image-metadata cache entries expire after up to 365 days. Expired entries are eligible for deletion and are not a personal trip database.
- Subscription entitlement records: The current record is kept while needed to maintain Rancang Plus. After the entitlement period ends, our target is to retain the parsed record for up to 395 days for entitlement disputes, accounting, security, and abuse prevention, then delete it through our retention process.
- Google Cloud Logging: Magebite Technology will configure the relevant project log buckets with a target retention period of 30 days. Google-managed required logs may follow Google's own retention rules and may not be changeable by Magebite Technology.
- Support emails and bug reports: Bug reports are created locally only after user action and are sent through the user's email provider. Mailbox retention target is 12 months after a support case is closed, subject to legal holds, security investigations, fraud prevention, or other lawful retention needs.
- Gemini project logs: Magebite Technology's target setting is to keep developer project request/response logging disabled. If logging is temporarily enabled for troubleshooting, it should be limited to 7 days, with no Gemini logs shared into datasets. Google may separately retain prompts, responses, and technical information for abuse monitoring or under applicable Google terms.
You may contact the Data Protection Officer to request review or deletion of backend data Magebite Technology
controls. Provider safety logs, immutable security records, and data required for legal, security, or
fraud-prevention purposes may be retained only to the extent genuinely necessary.
Google may temporarily retain Gemini API prompts, responses, and related technical information for abuse
prevention, safety enforcement, service operation, and legal compliance. Rancang does not intentionally
enable project-level Gemini request/response logging; if it is enabled temporarily, the target is no more
than 7 days. Google's retention and deletion practices are governed by its Gemini API terms and data
logging settings, which may apply independently of Rancang's settings.
Currency conversion sends only the requested date and technical request metadata needed for exchange-rate
lookup. Expense names and expense amounts are not sent for currency-rate lookup. The backend may cache
exchange-rate data.
Advertising, diagnostic, and ad measurement data processed by Google AdMob is retained by Google according
to Google's own policies and settings. We do not control Google's retention periods. We may see aggregated
ad reports in Google tools and keep them only as long as needed to understand app performance, advertising
performance, and business records.
8. Your Rights & Choices
Depending on where you live, including in the EU or UK, you may have rights to request access,
correction, deletion, restriction, portability, or objection to processing of your personal data. Where
processing is based on consent, you may withdraw that consent at any time.
- Access and manage your trip, checklist, and travel document data within the app
- Delete local app data by removing the app or deleting items within the app where available
- Review AI-imported travel details before approving and saving them locally
- Clear local diagnostic logs in the app where this control is available
- Choose whether to grant camera, selected photo, file picker, Contacts, and notification permissions
- Deny Contacts access or disable it later in iOS Settings
- Review or change advertising consent through Rancang's in-app Privacy Choices where available
- Opt out of personalized advertising through your device settings
- Manage tracking permissions through Apple's App Tracking Transparency settings
- Manage or cancel Rancang Plus subscriptions through your Apple ID or App Store subscription settings
- Disable widgets or Live Activities through iOS settings or by removing them from your device screens
- Contact us at 17hieng@gmail.com to make a privacy or deletion request, including requests related to Firebase anonymous UID quota records or support emails
Because most Rancang content is stored only on your device, Magebite Technology cannot access, export, or
delete that local content for you. You can manage or delete local content directly in the app or by deleting
the app from your device. For backend data Magebite Technology controls, email the Data Protection Officer to
request access, correction, deletion, restriction, portability where applicable, objection, or review of
processing. We will assess each request under applicable law. We may retain only the data genuinely needed
for legal obligations, security, fraud prevention, or to establish, exercise, or defend legal claims, and
will explain any applicable limitation.
9. Children
Rancang is not directed to children under 13. If you are under the age at which you can legally consent to
data processing in your country or region, you should use Rancang only with permission from a parent or
guardian. We do not knowingly collect personal data from children on our servers. If you believe a child
has provided personal data to us, contact us so we can review and delete it where appropriate.
Personalized advertising or tracking should not be enabled for users who are known to be under the
applicable digital consent age.
AI Travel Document Import and AI Travel Suggestions use backend AI services and are available only to users
aged 18 or older. Users under 18 must not use these AI features. Rancang uses a local self-attestation and
does not collect a date of birth; this is not a guarantee of a user's age.
10. International Transfers
Magebite Technology may use providers that process data outside Singapore, the EEA, and the United Kingdom,
including Google AdMob, Firebase, Google Cloud, Google Gemini, OpenAI where enabled, Apple, Frankfurter,
CurrencyAPI, Azure, OpenStreetMap/Overpass, Wikimedia Commons, Google Maps, and Waze. Magebite Technology
selects providers and uses legally appropriate contractual, adequacy, or other transfer safeguards where
required. The applicable safeguards depend on the provider, service, data, destination, and law governing
the transfer.
11. Data Sharing
We do not sell your personal data.
Data may be shared with third-party services only as necessary to provide app functionality, advertising,
subscriptions, AI parsing, exchange-rate lookup, security, and app stability. Local travel document
attachments, selected photos, expense photos, imported files, and checklist reminder content are not sold
or uploaded automatically by Rancang.
If you use AI Travel Document Import and tap Detect Details, extracted booking or travel document text,
a local trip identifier, subscription tier, and limited file metadata are sent to Firebase Cloud Functions,
and the extracted text is sent to Google Gemini for parsing. Original imported PDFs, photos, scans, files,
attachments, and local file URLs are not sent to Google Gemini for this feature. Google may temporarily
retain prompts, responses, and related technical information under its Gemini API terms and project
logging settings.
Firebase anonymous UID, Firebase Auth tokens, App Check tokens, subscription tier, AI quota metadata,
request metadata, and backend logs may be processed by Firebase, Firestore, Google Cloud, and related
Google services to operate backend features, enforce quotas, protect services, and troubleshoot issues.
Currency-rate lookup sends the requested date and technical request metadata only to our Firebase backend.
The app does not send expense names, expense amounts, trip details, or document contents for currency-rate
lookup. The backend may use Frankfurter or CurrencyAPI, and configured iOS releases may use the Azure
endpoint protected by Apple App Attest. It may cache returned exchange-rate data.
When you request AI travel suggestions, the destination city, country or region, language, and technical
request metadata may be sent to Firebase and the active AI provider. Suggestions may be cached in Firestore
and image metadata may be requested from Wikimedia Commons. When you request supplemental place details,
selected place names and coordinates may be sent to OpenStreetMap/Overpass. When you choose external
navigation, selected names, search terms, and coordinates may be sent to Apple Maps, Google Maps, or Waze.
Calendar information accessed by Add to Calendar is not uploaded to Rancang, stored on Rancang's servers,
or shared through Rancang's servers. Events created by Rancang are stored in your default calendar and may
be synchronized by your calendar provider according to that provider's privacy policy.
Contacts are read locally on your device and are not uploaded to our servers or shared with third parties.
Only names you choose to add are saved as bill split data.
If you choose to send a bug report, your email app sends the report to us, and we use it only for customer
support and troubleshooting.
Technical request data may be processed by Firebase and Google Cloud services to provide AI import,
currency exchange-rate features, app integrity checks, quota tracking, and backend abuse prevention.
Subscription purchases and entitlement validation are handled through Apple StoreKit and App Store
services. A verified transaction JWS and random app-account token may be sent to Firebase for validation;
the backend stores parsed entitlement fields rather than the raw JWS.
Widget and Live Activity data is stored locally for app extension display and is not uploaded
automatically by Rancang.
12. Complaints
If you are in the EU or UK and believe your data protection rights have not been respected, you may contact
us first at 17hieng@gmail.com. You also have the right to lodge a
complaint with your local data protection supervisory authority.
13. Changes to This Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new
Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this page
periodically for any changes.