1. Who We Are
Rancang is operated by Magebite Technology. For this policy, Magebite Technology is the
data controller for personal data we decide how and why to process. You can contact us at
17hieng@gmail.com for privacy questions or requests.
Data Protection Officer:
Magebite Technology has designated Eii Chee Hieng as its Data Protection Officer.
Privacy and data-protection requests:
17hieng@gmail.com. The Data Protection Officer handles privacy
requests, complaints, retention questions, and other data-protection matters. If we appoint an EU or UK
representative, or if one is legally required for Rancang, we will publish the representative contact
details in this policy.
2. Information We Collect
We collect or process information only when needed for app features, advertising, or app stability:
-
User-Created Content:
Trip details, expenses, custom categories, currency selections, checklist items,
checklist reminder settings, bill split records, bill split participants, paid/share amounts,
settlement records, travel document records, and Rancang Plus subscription status or entitlement
state where relevant to features you use in the app. Most user-created app content is stored locally
on your device. We do not have access to your local content unless you separately choose to share it
with us or use a feature that sends limited information to our backend, such as AI Travel Document
Import or currency exchange-rate lookup as described below.
-
Account Information:
If you create or link an account, Firebase Authentication processes your Firebase user ID and the
sign-in method you use, such as email/password or Sign in with Apple. Depending on the information you
provide, the account may include an email address, display name, and profile photo. Rancang uses this
information to sign you in, preserve your account library, support collaboration, restore purchases,
and process account-deletion requests. Anonymous Firebase sessions may still be used before an account
is linked for limited feature access and quota protection.
-
Cloud Sync:
Cloud Sync is optional and requires a non-anonymous account. If you enable it, Rancang encrypts your
library on your device before uploading encrypted archives, file chunks, and the metadata needed to
synchronize them. Depending on your protection mode, account recovery or a recovery key may be used to
unlock the library on another device. The backend can process account identifiers, archive versions,
encrypted manifests, content hashes, sizes, revisions, and operational timestamps, but the encrypted
archive contents are not intentionally readable by Rancang.
-
Shared Trips:
If you create or join a shared trip, Rancang processes the shared-trip identifier, membership role,
Firebase user ID, display name, optional profile photo URL, and last-sync activity so collaborators can
be shown in the app. The trip owner chooses whether to share trip plans, expenses, wallets, photos,
and individual travel documents. Shared-trip archives and attachments are encrypted before upload, but
collaborators can access the content that the owner shares with them through the app.
-
Contacts:
If you grant Contacts access, Rancang reads contact names and nicknames on your device to suggest
friends when you add people to a bill split. Contacts are read locally on your device. Rancang does
not upload your contacts, share them with third parties, or store your full contacts list. Only names
you choose to add are saved as part of your bill split data. You can deny Contacts access or disable
it anytime in iOS Settings.
-
AI Travel Document Import:
If you choose to import travel details from a PDF, photo, local file, or pasted booking text, Rancang
first reads or extracts text locally on your device using Apple frameworks where available. Original
imported PDFs, photos, scans, or files may be stored locally as travel document attachments if you
choose to keep them in Rancang. Those original PDFs, photos, files, local file URLs, and attachments
are not uploaded for AI parsing. When you tap Detect Details, Rancang sends only the extracted text
and limited metadata to a Firebase Cloud Function named parse_travel_document. The request may include
the extracted text, a local trip identifier, source type, optional file name, MIME type, file size, subscription
tier, and compatibility metadata such as protocol version, app version, build number, or platform where
received. The local trip identifier is a randomly generated identifier for the trip, not your Firebase
account identifier. The backend sends the extracted text to Google Gemini to parse travel
details. Parsed results are returned to you for review, and only items you approve are saved locally in
the app. AI Travel Document Import is available only to users aged 18 or older.
-
Anonymous Sessions and AI Quota:
Rancang may silently create or reuse an anonymous Firebase session before you link an account. The
anonymous Firebase UID can be used to track monthly AI import usage, such as 3 imports per month for
free users and 100 imports per month for Rancang Plus users. Backend quota records may store the UID,
month, usage count, subscription tier, and related request metadata needed to operate and protect the
feature. We store AI usage metrics such as token counts and request counts for quota, billing, abuse
prevention, and service monitoring. Firebase callable requests may automatically include Firebase Auth
and App Check tokens when available.
-
AI Travel Suggestions:
When you view destination suggestions, Rancang may send the destination city, country or region,
requested app language, a local Firebase anonymous UID, and compatibility metadata to a Firebase
Cloud Function. The backend may send the destination and language to its configured AI provider,
such as Google Gemini or OpenAI, to generate suggested places. Results may be stored in a shared
Firestore cache for up to 365 days and can include place names, descriptions, addresses, coordinates,
and image-attribution metadata. This feature is available only to users aged 18 or older.
-
Backend Service-Usage and Operational Data:
Rancang may associate limited backend service-usage and operational data with a Firebase anonymous user
identifier. This may include AI import request counts; safe lifecycle stages and error codes; input,
output, thinking, cached, and total token usage; AI quota and subscription-period usage; Visa and entry
requirement request counts and safe route/status metadata; protocol or app metadata where received; source
type and MIME type where received; request timestamps, request duration, and technical diagnostics; and
abuse-prevention and service-security metadata. This information is used to provide and operate app
features, enforce AI quotas and subscription limits, detect abuse, protect backend services, troubleshoot
reliability, perform aggregate product and service analysis, and monitor billing or AI cost where
applicable. It is not sold and is not used for advertising unless separately disclosed in this policy.
The current backend does not maintain a separate per-user AI success/failure counter; safe success and
failure stages may appear in operational logs.
-
Widget and Live Activity Data:
If you enable widgets or Live Activities, Rancang may store limited local snapshots, such as trip or
flight countdown and progress information, in the app group container so app extensions can display
current trip-related information. This is local, on-device app extension storage and is not uploaded
automatically by Rancang.
-
Travel Document Attachments:
If you choose to take a photo, scan a document, select a photo, or import a file for a travel
document, the selected image, scan, PDF, or file is copied into app storage as a local travel document
attachment. These original attachments are not uploaded automatically, including when AI Travel
Document Import sends extracted text for parsing.
-
Expense Photos:
If you choose to take or attach a photo for an expense, the photo is stored locally in app storage.
Expense photos are not uploaded automatically and are not accessible to us unless you choose to share
them with us, such as through a support request.
-
Bug Reports, Support Requests, and Local Logs:
Rancang may keep local diagnostic logs on your device. Logs are capped, rotated, and are not uploaded
automatically. If you choose to send a bug report, Rancang creates a local diagnostic report and opens
your email app so you can review and send it. The report may include your written description, app
version, build number, bundle ID, device model, iOS version, locale, and recent redacted local logs.
Your email address is visible to us when you send the email. Bug reports are not sent automatically.
Backend production telemetry and Cloud Logging use allowlisted operational fields and must not
intentionally contain raw OCR text, travel-document contents, AI prompts, AI responses, original PDFs,
photos or scans, authentication tokens, App Check tokens, API keys, full request payloads, or filenames
containing personal information. Local logs are intended to follow the same minimization rule; do not
include confidential information in a support description.
-
Device, Advertising, and Consent Information:
Free users may see Google AdMob ads. Google AdMob, Google's User Messaging Platform, and related
Google services may process device identifiers, advertising identifiers, IP address, approximate
location, app interaction information, diagnostic information, consent choices, and ad performance
information, depending on your device settings, consent choices, and Google's policies. Rancang may
request App Tracking Transparency / IDFA permission for personalized ads where applicable. Rancang Plus disables ads. Ads remain disabled in the app while an active entitlement is available.
3. Device Permissions
Rancang asks for device permissions only when they are needed for features you choose to use:
-
Camera:
Used when you choose to take an expense photo, take a travel document photo, or scan a travel document.
The camera is used only when you choose one of these actions.
-
Selected Photos:
Used for the trip banner photo picker, expense photo attachment, and travel document Select from
Gallery feature. On iOS, Rancang uses PhotosPicker, so the app reads only the photo or photos you
explicitly select and does not require broad photo library access.
-
Selected Files and Documents:
Used when you choose Import File for a travel document. Rancang accesses only the file selected
through the system file picker and copies it into app storage.
-
Contacts:
Used only if you grant access, to read contact names and nicknames locally and suggest friends when
adding people to a bill split. Rancang does not upload your contacts or store your full contacts list.
You can deny or later disable Contacts access in iOS Settings.
-
Calendar Access:
When you choose Add to Calendar, Rancang requests access to your device calendars. Rancang uses this
access to create an all-day event containing your trip name, destination, travel dates, and a Rancang
trip identifier. Rancang may also check events within the relevant date range solely to prevent the
same trip from being added more than once. Calendar information accessed by this feature is processed
on your device and is not transmitted to, stored on, or shared through Rancang's servers. Events
created by Rancang are stored in your default calendar and may be synchronized by your calendar
provider according to that provider's privacy policy. You can revoke Rancang's Calendar access at any
time in Settings > Privacy & Security > Calendars > Rancang. You can remove an exported trip by
deleting the event from Calendar.
-
Location:
When you use nearby-place suggestions while recording an expense, Rancang may request When In Use
location access to find relevant places. Location is used for that request only; Rancang does not use
background location. Map search and selected-place features can also use the place names or coordinates
that you choose without requesting continuous location access.
-
Notifications:
Used for local checklist, trip, flight, and travel-document reminders that you select or enable in the
app. If you use shared-trip bill splitting, Rancang may also register an Apple/ Firebase notification
token and send a payment reminder to selected trip participants. Notification content may include
relevant trip, flight, checklist, travel-document, or bill-split reminder information. You can manage
notification permission in your device settings. Turning permission off stops delivery on the device,
but the registered token is not currently removed immediately. It may remain until provider or backend
token cleanup; the current account-deletion path does not explicitly remove this top-level device-token
record.
-
App Tracking Transparency / IDFA:
Used on iOS to request permission before accessing the advertising identifier or allowing tracking
across apps and websites for personalized ads and ad measurement. If you deny tracking permission,
ads may still be shown without cross-app tracking.
4. Third-Party Services
We use the following third-party services:
-
Google AdMob and User Messaging Platform:
Used to display advertisements to free users, request and manage advertising consent where required,
and measure ad performance. AdMob may process device and advertising information to provide,
personalize, limit, and measure ads, depending on your consent choices and device settings. If you do
not consent to personalized ads or tracking, Rancang may request non-personalized or limited ads where
allowed, or may not request ads if consent is required and has not been granted. Rancang Plus disables ads while an active subscription entitlement is available. Google's handling of this data is governed
by Google's privacy policies and advertising terms.
-
Firebase Authentication:
Firebase Authentication provides anonymous sessions before account linking and supports user-facing
email/password and Sign in with Apple accounts. Firebase processes the Firebase user ID and account
profile fields that you provide, such as email address, display name, and profile photo. Rancang uses
this identity to protect account data, restore purchases, enable Cloud Sync, and authorize shared-trip
collaboration.
-
Firebase App Check:
Firebase App Check helps protect callable endpoints. Firebase may process app-integrity signals and App
Check tokens that accompany callable requests. Rancang does not intentionally store App Check tokens in
application logs.
-
Firebase Cloud Functions:
Rancang uses callable Cloud Functions for AI travel-document parsing, AI travel suggestions,
exchange-rate lookup, Visa and entry-requirement lookup, Cloud Sync, shared-trip collaboration,
notification-device registration, bill-split reminders, account deletion, and related backend
operations. Depending on the feature, requests may include extracted text, a local trip identifier,
destination city and country, requested language, source and file metadata, a requested currency date,
Visa route and purpose data, account and membership identifiers, subscription tier, protocol metadata,
and Firebase Auth or App Check context.
-
Encrypted Cloud Sync and Firebase Storage:
When you enable Cloud Sync, Rancang uploads encrypted library archives and encrypted file chunks to
Firebase services. Firestore stores the account's sync metadata, encrypted manifests, revisions,
recovery-key envelopes, and operation records. Firebase Storage stores encrypted archive chunks and
shared-trip attachment chunks. Rancang's backend validates sizes, hashes, revisions, and access
permissions but does not intentionally parse the encrypted library contents.
-
Firebase Cloud Messaging / Apple Push Notification service:
If you enable notifications and use shared-trip bill splitting, Rancang registers an app-device
notification token with Firebase and may use it to deliver a payment reminder to selected trip
participants. The reminder request includes the recipient account IDs, shared-trip and trip
identifiers, and the short title and body chosen for the reminder. Firebase and Apple process delivery
data under their own terms.
-
Firestore:
Firestore stores backend records such as AI quota and token-usage summaries, Visa requirement check
history, cached exchange rates, account and subscription records, Cloud Sync metadata, shared-trip
membership and invitation records, notification-device records, and operational configuration.
Encrypted archives and encrypted attachments are stored separately as opaque data. Firestore records
do not contain the original travel-document PDF, photo, scan, or raw OCR attachment from AI Import.
-
Google Cloud Logging:
Google Cloud Logging receives safe operational logs for backend monitoring and troubleshooting, including
request stages, error codes, durations, source type, MIME type, text length, token metrics, and service
metadata. Rancang does not intentionally log raw OCR text, travel-document contents, AI prompts or
responses, original files, authentication or App Check tokens, API keys, or full request payloads.
-
Google Gemini API:
When you tap Detect Details for AI Travel Document Import, the backend sends extracted travel document
text to Google Gemini to parse booking or travel details. For AI Travel Suggestions, the backend may
send destination and language requests to Google Gemini when that provider is active. Original imported
PDFs, photos, scans, files, attachments, and local file URLs are not sent to Google Gemini for document
parsing. Google may temporarily
log prompts, responses, and related technical information for abuse prevention, safety enforcement,
service operation, and legal compliance under the Gemini API terms. The backend does not intentionally
enable project-level Gemini request and response logging. If project logging is enabled temporarily for
troubleshooting, it is configured for the shortest practical period and no longer than 7 days. Google
may independently retain prompts, responses, and technical information for abuse prevention, safety
enforcement, service operation, and legal compliance; Google's retention depends on the applicable
Gemini API service and terms.
-
OpenAI API where enabled:
The backend may use an OpenAI model for AI Travel Suggestions if the active server rollout selects one.
In that case, the destination, country or region, requested language, and prompt needed to generate
suggestions are processed by OpenAI under its applicable API terms and privacy documentation.
-
Exchange-Rate and Transit Providers:
Rancang retrieves exchange-rate data through our Firebase backend. The backend may use Frankfurter or
CurrencyAPI and cache the returned rate data. Configured iOS releases may also use an Azure-hosted
Rancang endpoint for currency and transit estimates. The Azure endpoints use Apple App Attest
attestation or assertion data to help protect the service. Currency requests contain the requested
date and technical request data, not expense names, expense amounts, trip details, or document contents.
Transit requests may contain selected route coordinates, departure time, travel mode, and locale.
-
AI Travel Suggestions and Wikimedia Commons:
The travel-suggestion backend may use Google Gemini or OpenAI according to the active server rollout.
It may query the Wikimedia Commons API and Wikimedia image hosts using place and destination terms to
find public image metadata. Returned image URLs, author, license, and attribution information may be
cached with the suggestion. Wikimedia and image-host processing is governed by those providers' own
terms and privacy policies.
-
OpenStreetMap and Overpass:
When Rancang looks up supplemental place details, it may send a selected place name and selected or
resolved coordinates to the Overpass API at OpenStreetMap. Results may include opening hours, phone,
website, and image or Wikimedia Commons tags. Rancang does not request your current device location for
this feature. OpenStreetMap, Overpass, and any image host involved process requests under their own
policies.
-
Visa and Entry Requirements Backend:
Rancang uses a Firebase Cloud Function backed by Firestore-curated travel guidance. The backend may
receive passport country, destination country, travel purpose, optional departure and return dates, and
locale. It stores a check record associated with the Firebase anonymous UID containing route, purpose,
result status, and check timestamps. It is not an external Visa API and does not require passport
numbers, traveller names, or document scans for this feature.
-
Apple Maps and Geocoding Services:
When the app displays maps, searches for a place, or resolves a trip or expense location, Apple
services may process place names, addresses, search queries, and selected or resolved map coordinates
to return map and geocoding results. Rancang does not request your current device location for these
map features.
-
External Navigation Apps:
When you choose to open a place or route in Apple Maps, Google Maps, or Waze, Rancang passes the
selected place or route names, search terms, and/or coordinates to the app or URL you selected. The
selected provider may process that information under its own privacy policy. Rancang does not send
these navigation requests automatically.
-
Apple App Store / StoreKit:
Rancang uses Apple StoreKit and the App Store to offer, purchase, restore, and validate Rancang Plus
subscriptions, the Lifetime plan, and one-time AI credit packs. Apple may process purchase,
subscription, transaction, Apple ID, device, and
payment-related information according to Apple's own privacy policy and App Store terms. Rancang
receives only the product, transaction, entitlement, and credit information needed to unlock Rancang
Plus features, hide ads for subscribers, add purchased AI credits, and restore purchases. When server
validation is needed, Rancang sends a verified StoreKit transaction JWS and a random app-account token
to Firebase. The backend verifies the JWS and stores parsed entitlement, transaction, and credit
fields; it does not retain the raw JWS after validation.
5. Legal Bases for Processing
If EU or UK data protection law applies, we rely on the following legal bases:
-
Performance of a contract:
To provide app features you request, such as saving trips, expenses, checklists, travel documents, AI
travel suggestions, AI import parsing, Cloud Sync, shared-trip collaboration, bill-split reminders,
subscription and Lifetime entitlements, AI credit balances, and exchange-rate lookup.
-
Consent:
For permissions such as notifications, location, camera access, selected photos, selected files, contacts,
calendar access, and tracking
or personalized advertising where consent is required. You can withdraw or change advertising consent
through Rancang's in-app Privacy Choices where available, and you can manage device permissions through
your device settings.
-
Legitimate interests:
To keep the app functional, improve reliability, prevent abuse, enforce AI import quotas, protect backend services, cache exchange-rate data, and show non-personalized ads where allowed by law and your settings.
-
Legal obligation:
To comply with applicable laws, regulatory requests, or enforceable legal processes if they apply.
6. How We Use Information
- Provide and maintain app functionality
- Store and display trip, checklist, and travel document information you add in the app
- Parse extracted travel document text when you choose AI Travel Document Import
- Store and display bill split and settlement information you add in the app
- Authenticate accounts, preserve account libraries, and process account deletion
- Synchronize encrypted libraries and attachments when you enable Cloud Sync
- Share selected trip content with collaborators when you create or join a shared trip
- Suggest friend names from local contacts when you add people to a bill split, if you grant Contacts access
- Schedule local checklist reminder notifications when you choose to set reminders
- Register notification devices and deliver bill-split reminders to selected trip participants
- Use your location while in the app to suggest nearby places for an expense when you grant permission
- Display trip or flight-related information in widgets and Live Activities when enabled
- Create calendar events for trips when you choose Add to Calendar
- Manage Rancang Plus subscriptions, the Lifetime plan, AI credit purchases, feature unlocks, and purchase restoration
- Create or reuse Firebase sessions and accounts to protect backend services and associate your library with your account
- Operate, secure, and analyze backend service usage, AI quota usage, token metrics, and reliability signals
- Count and review Visa and entry-requirement checks using safe route and result metadata
- Retrieve and cache currency exchange-rate data for requested dates
- Generate destination suggestions and related place-image metadata when you request travel suggestions
- Improve app performance and user experience
- Respond to bug reports and support requests
- Diagnose app errors using user-submitted diagnostic reports and recent redacted local logs you choose to send
- Display advertisements that support the app
- Measure ad performance and prevent ad-related fraud or abuse
7. Data Storage & Retention
Most trip, expense, expense photo, checklist, bill split, settlement, travel document, selected photo, scan,
and imported file data is stored locally on your device. We do not have access to local
content unless you separately choose to share it with us or use a feature that sends limited information to
our backend, such as AI Travel Document Import, Cloud Sync, shared-trip collaboration, bill-split reminders,
or currency exchange-rate lookup.
Cloud Sync is optional. When enabled, encrypted library archives, attachments, profile data, and shared
library metadata are uploaded to Firebase services for synchronization. Turning Cloud Sync off stops future
synchronization from that device but does not currently delete the existing cloud library. The cloud copy
remains while the account exists unless it is removed through account deletion or another supported backend
cleanup process. Account deletion removes the account's Cloud Sync metadata and private cloud-storage
objects through a resumable deletion process.
Shared-trip invitations expire after 7 days. Shared-trip operation records used for safe retries are
pruned after approximately 30 days. Shared-trip membership, encrypted manifests, and encrypted attachment
chunks remain while the shared trip and its memberships are active, unless the owner removes them or the
owning account is deleted. Other collaborators may retain local copies of content already downloaded to
their devices.
For AI Travel Document Import, original imported PDFs, photos, scans, files, and local file URLs may be
stored locally as travel document attachments if you choose to keep them in Rancang, but they are not
uploaded for AI parsing. If you tap Detect Details, only extracted text, a local trip identifier, compatibility metadata where received, and
limited file metadata are sent to our Firebase backend and then the extracted text is sent to Google Gemini
for parsing. Parsed results are returned for your review. Only items you approve are saved locally in
Rancang.
For AI Travel Suggestions, destination and language requests may be processed by Firebase and the active AI
provider. Generated place data and image-attribution metadata may be stored in a shared Firestore cache for
up to 365 days. This cache is not linked to your local trip content and is not a personal trip database.
Rancang may also store limited local widget and Live Activity snapshots, such as trip or flight countdown
and progress information, in the app group container so widgets and Live Activities can display current
trip-related information. This is local, on-device app extension storage and is not uploaded automatically
by Rancang.
Rancang does not store your full contacts list. If you grant Contacts access, contact names and nicknames
are read locally on your device only to suggest friends when adding people to a bill split. Only friend
names you choose to add are saved as part of local bill split data. Contacts are not uploaded automatically.
Calendar information accessed by Add to Calendar is processed on your device. Rancang may check events
within the relevant trip date range only to avoid adding the same trip more than once. Calendar information
accessed by this feature is not transmitted to, stored on, or shared through Rancang's servers. Events
created by Rancang are stored in your default calendar and may be synchronized by your calendar provider.
Images, scans, and imported files added to travel documents are copied into app storage and are not
uploaded automatically unless you enable Cloud Sync or explicitly share the document through a shared
trip. Local trip, expense, checklist, bill split, settlement, document, photo, scan, and imported file data
remains on your device until you delete the item, clear the relevant data, or remove the app, unless it has
been backed up through your device backup services.
Local diagnostic logs are capped, rotated, and can be cleared in the app where the feature is available.
Bug reports and support emails are retained only as long as reasonably needed for customer support,
troubleshooting, legal, security, and business record purposes.
Firebase anonymous account identifiers, AI quota documents, AI usage metrics such as request counts and
input, output, thinking, cached, and total token counts, Visa requirement check records, backend request
metadata, and Google Cloud logs may be retained to operate features, enforce quotas and subscription limits,
monitor costs, prevent abuse, secure services, troubleshoot errors, and comply with legal obligations. Our
retention target for user-linked backend records is described below. Deletion may require a manual request
until the relevant automated retention control is active.
Current retention status:
- User AI usage summaries and quota records: Our target is to retain per-user Firestore records for up to 395 days from their latest update for quota, billing, abuse prevention, and service monitoring, then delete them through our retention process.
- Visa requirement checks: Our target is to retain per-user check records for up to 395 days from their latest update, then delete them through our retention process.
- Travel suggestions: Shared destination suggestion and image-metadata cache entries expire after up to 365 days. Expired entries are eligible for deletion and are not a personal trip database.
- Subscription entitlement records: The current record is kept while needed to maintain Rancang Plus. After the entitlement period ends, our target is to retain the parsed record for up to 395 days for entitlement disputes, accounting, security, and abuse prevention, then delete it through our retention process.
- Cloud Sync libraries: Encrypted account library metadata, manifests, and storage objects remain while the account's Cloud Sync data is needed to provide the service. Turning sync off does not currently delete the existing cloud library. Account deletion starts removal of the account metadata and private cloud-storage objects through a resumable cleanup process.
- Shared-trip invitations and operations: Invitations expire after 7 days, and idempotency operation records are pruned after approximately 30 days. Active shared-trip membership and encrypted shared content remain until the trip is changed or deleted, a member is removed, or the relevant account and owned trip data are deleted.
- Notification-device records: A registered notification token may remain while the account is active. Disabling notification permission stops delivery on the device but does not currently trigger immediate server-side token deletion. Invalid or malformed records may be removed during backend cleanup. The current account-deletion path does not explicitly remove the top-level notification-device record, so deletion requests may require a separate cleanup action.
- AI credit and purchase records: Parsed purchase, entitlement, and credit-balance records are kept while needed to provide credits, restore purchases, resolve disputes, prevent abuse, and maintain accounting, then handled under the subscription-entitlement retention target where applicable.
- Google Cloud Logging: Magebite Technology will configure the relevant project log buckets with a target retention period of 30 days. Google-managed required logs may follow Google's own retention rules and may not be changeable by Magebite Technology.
- Support emails and bug reports: Bug reports are created locally only after user action and are sent through the user's email provider. Mailbox retention target is 12 months after a support case is closed, subject to legal holds, security investigations, fraud prevention, or other lawful retention needs.
- Gemini project logs: Magebite Technology's target setting is to keep developer project request/response logging disabled. If logging is temporarily enabled for troubleshooting, it should be limited to 7 days, with no Gemini logs shared into datasets. Google may separately retain prompts, responses, and technical information for abuse monitoring or under applicable Google terms.
You may contact the Data Protection Officer to request review or deletion of backend data Magebite Technology
controls. Provider safety logs, immutable security records, and data required for legal, security, or
fraud-prevention purposes may be retained only to the extent genuinely necessary.
Google may temporarily retain Gemini API prompts, responses, and related technical information for abuse
prevention, safety enforcement, service operation, and legal compliance. Rancang does not intentionally
enable project-level Gemini request/response logging; if it is enabled temporarily, the target is no more
than 7 days. Google's retention and deletion practices are governed by its Gemini API terms and data
logging settings, which may apply independently of Rancang's settings.
Currency conversion sends only the requested date and technical request metadata needed for exchange-rate
lookup. Expense names and expense amounts are not sent for currency-rate lookup. The backend may cache
exchange-rate data.
Advertising, diagnostic, and ad measurement data processed by Google AdMob is retained by Google according
to Google's own policies and settings. We do not control Google's retention periods. We may see aggregated
ad reports in Google tools and keep them only as long as needed to understand app performance, advertising
performance, and business records.
8. Your Rights & Choices
Depending on where you live, including in the EU or UK, you may have rights to request access,
correction, deletion, restriction, portability, or objection to processing of your personal data. Where
processing is based on consent, you may withdraw that consent at any time.
- Access and manage your trip, checklist, and travel document data within the app
- Delete local app data by removing the app or deleting items within the app where available
- Review AI-imported travel details before approving and saving them locally
- Clear local diagnostic logs in the app where this control is available
- Choose whether to grant camera, selected photo, file picker, Contacts, location, and notification permissions
- Deny Contacts access or disable it later in iOS Settings
- Turn Cloud Sync off; turning it off stops future synchronization but does not currently delete the existing cloud library
- Delete your account from the app, which starts deletion of the account records, Cloud Sync data, and owned shared-trip data controlled by Rancang; notification-device records may require separate cleanup
- Leave a shared trip or ask its owner to remove your membership
- Review or change advertising consent through Rancang's in-app Privacy Choices where available
- Opt out of personalized advertising through your device settings
- Manage tracking permissions through Apple's App Tracking Transparency settings
- Manage or cancel Rancang Plus subscriptions and review purchases through your Apple ID or App Store settings
- Disable widgets or Live Activities through iOS settings or by removing them from your device screens
- Contact us at 17hieng@gmail.com to make a privacy or deletion request, including requests related to account, Cloud Sync, shared-trip, notification, AI credit, quota, or support records
Because most Rancang content is stored only on your device, Magebite Technology cannot access, export, or
delete that local content for you. You can manage or delete local content directly in the app or by deleting
the app from your device. For account, Cloud Sync, shared-trip, notification, purchase, and other backend
data Magebite Technology controls, email the Data Protection Officer to
request access, correction, deletion, restriction, portability where applicable, objection, or review of
processing. We will assess each request under applicable law. We may retain only the data genuinely needed
for legal obligations, security, fraud prevention, or to establish, exercise, or defend legal claims, and
will explain any applicable limitation.
9. Children
Rancang is not directed to children under 13. If you are under the age at which you can legally consent to
data processing in your country or region, you should use Rancang only with permission from a parent or
guardian. We do not knowingly collect personal data from children on our servers. If you believe a child
has provided personal data to us, contact us so we can review and delete it where appropriate.
Personalized advertising or tracking should not be enabled for users who are known to be under the
applicable digital consent age.
AI Travel Document Import and AI Travel Suggestions use backend AI services and are available only to users
aged 18 or older. Users under 18 must not use these AI features. Rancang uses a local self-attestation and
does not collect a date of birth; this is not a guarantee of a user's age.
10. International Transfers
Magebite Technology may use providers that process data outside Singapore, the EEA, and the United Kingdom,
including Google AdMob, Firebase, Google Cloud, Google Gemini, OpenAI where enabled, Apple, Frankfurter,
CurrencyAPI, Azure, OpenStreetMap/Overpass, Wikimedia Commons, Google Maps, and Waze. Magebite Technology
selects providers and uses legally appropriate contractual, adequacy, or other transfer safeguards where
required. The applicable safeguards depend on the provider, service, data, destination, and law governing
the transfer.
11. Data Sharing
We do not sell your personal data.
Data may be shared with third-party services only as necessary to provide app functionality, advertising,
subscriptions, AI parsing, exchange-rate lookup, security, collaboration, and app stability. Local travel
document attachments, selected photos, expense photos, imported files, and checklist reminder content are
not sold or uploaded automatically by Rancang unless you enable Cloud Sync or explicitly share the content
through a shared trip.
If you use AI Travel Document Import and tap Detect Details, extracted booking or travel document text,
a local trip identifier, subscription tier, and limited file metadata are sent to Firebase Cloud Functions,
and the extracted text is sent to Google Gemini for parsing. Original imported PDFs, photos, scans, files,
attachments, and local file URLs are not sent to Google Gemini for this feature. Google may temporarily
retain prompts, responses, and related technical information under its Gemini API terms and project
logging settings.
Firebase anonymous UID, Firebase Auth tokens, App Check tokens, subscription tier, AI quota metadata,
request metadata, and backend logs may be processed by Firebase, Firestore, Google Cloud, and related
Google services to operate backend features, enforce quotas, protect services, and troubleshoot issues.
When Cloud Sync is enabled, encrypted library archives, encrypted file chunks, content hashes, revisions,
and account-linked sync metadata are sent to Firebase services. When you use a shared trip, the backend
processes encrypted shared-trip manifests and attachments plus the membership metadata needed to authorize
collaborators. The trip owner controls which documents and trip content are shared with participants.
When you send a bill-split reminder, Firebase Cloud Functions checks that the recipients belong to the
shared trip and uses their registered notification tokens to request delivery through Firebase Cloud
Messaging and Apple Push Notification service. The reminder does not include the encrypted trip archive;
it contains only the short title and body supplied for the notification together with delivery identifiers.
Currency-rate lookup sends the requested date and technical request metadata only to our Firebase backend.
The app does not send expense names, expense amounts, trip details, or document contents for currency-rate
lookup. The backend may use Frankfurter or CurrencyAPI, and configured iOS releases may use the Azure
endpoint protected by Apple App Attest. It may cache returned exchange-rate data.
When you request AI travel suggestions, the destination city, country or region, language, and technical
request metadata may be sent to Firebase and the active AI provider. Suggestions may be cached in Firestore
and image metadata may be requested from Wikimedia Commons. When you request supplemental place details,
selected place names and coordinates may be sent to OpenStreetMap/Overpass. When you choose external
navigation, selected names, search terms, and coordinates may be sent to Apple Maps, Google Maps, or Waze.
Calendar information accessed by Add to Calendar is not uploaded to Rancang, stored on Rancang's servers,
or shared through Rancang's servers. Events created by Rancang are stored in your default calendar and may
be synchronized by your calendar provider according to that provider's privacy policy.
Contacts are read locally on your device and are not uploaded to our servers or shared with third parties.
Only names you choose to add are saved as bill split data.
If you choose to send a bug report, your email app sends the report to us, and we use it only for customer
support and troubleshooting.
Technical request data may be processed by Firebase and Google Cloud services to provide AI import,
currency exchange-rate features, app integrity checks, quota tracking, and backend abuse prevention.
Subscription, Lifetime, and AI-credit purchases and entitlement validation are handled through Apple
StoreKit and App Store services. A verified transaction JWS and random app-account token may be sent to
Firebase for validation; the backend stores parsed entitlement, transaction, and credit fields rather than
the raw JWS.
Widget and Live Activity data is stored locally for app extension display and is not uploaded
automatically by Rancang.
12. Complaints
If you are in the EU or UK and believe your data protection rights have not been respected, you may contact
us first at 17hieng@gmail.com. You also have the right to lodge a
complaint with your local data protection supervisory authority.
13. Changes to This Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new
Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this page
periodically for any changes.