TakeOff is local-first. Most travel data stays on your device. Apple Suggestions is enabled by default and contributes basic travel activity to Apple system services; you can turn it off in Settings. iCloud sync remains optional.

1. Contact

TakeOff is an independent app for iPhone and Mac. Questions about privacy or data handling can be sent to contact@sinuk.dev.

2. Data you store in TakeOff

TakeOff stores app data locally with Apple's SwiftData framework, including visited countries, trips, checklist items, budgets, saved clocks, saved locations, and travel document metadata.

Travel document image data is stored locally with the rest of your TakeOff data and is protected by iOS device data protection on iPhone. Documents are visible while the app is open and do not require separate authentication. TakeOff does not operate a TakeOff account server and cannot read the data stored only on your device.

3. Optional iCloud sync

If you enable iCloud sync, supported TakeOff data syncs through Apple's private CloudKit database for your Apple ID. One iCloud Sync switch controls supported travel data. When TakeOff Pro is active, that switch also enables document sync; document sync is unavailable without Pro. You can keep TakeOff local-only by turning the switch off.

TakeOff does not receive your iCloud data. To remove iCloud data, use Apple's iCloud storage management tools for the app.

4. Diagnostics and product analytics

On iPhone, release builds use Firebase Performance Monitoring to measure fixed map, trip, import and export operations and their completion outcomes. Automatic network-request and screen instrumentation is disabled. Firebase receives performance measurements, installation identifiers, app/device/operating-system information, and connection information used for approximate geographic grouping. TakeOff does not add trip identifiers, destinations, booking details, document contents, file names, or request URLs to these traces.

On iPhone and Mac, TakeOff keeps small local summaries of system performance and diagnostic reports from Apple's MetricKit for up to 14 days. These summaries can include launch and hang timings, CPU/GPU time, available memory measurements, and diagnostic counts. They are included when you choose to send feedback. Delete All Data clears the local summaries.

Release builds use Firebase Crashlytics to help diagnose crashes. Crash reports may include device model, operating system version, app version, stack traces, and diagnostic identifiers. TakeOff does not attach your trip notes, document contents, budgets, or route contents to crash reports.

On iPhone, release builds also use Firebase Analytics for app opens, feature access, paywall display, purchase events, country-marking events (including the country code), and affiliate link impressions/taps. Google Analytics automatically collects app instance identifiers, device/app information, approximate geography, and purchase/subscription events, including product identifiers and values. These analytics records can be associated with an installation identifier. TakeOff uses Firebase Analytics without Ad ID support and does not use it for advertising tracking. TakeOff does not send trip notes, document contents, individual expense contents, or saved itinerary routes as analytics payloads.

Firebase may create installation, app instance, diagnostic, and anonymous authentication identifiers so TakeOff can protect Firebase-backed services, deliver Remote Config values, and group crash or product-health signals. TakeOff does not require a user account, does not create a public profile from anonymous Firebase Auth, and does not sell these identifiers.

5. Purchases

TakeOff Pro purchases and restores are processed by Apple's StoreKit. TakeOff does not receive or store your payment card information. Firebase Analytics may automatically record purchase and subscription events; these are separate from payment card data.

6. Permissions

TakeOff asks for permissions only when related features need them: location for travel tools, camera and photo library for trip/document workflows and optional import, Health access for workout-route country import, notifications for document expiry, trip preparation, and jet lag reminders, and Calendar access when you choose to add or synchronize trip or jet lag events.

HealthKit access is read-only and limited to workout routes you choose to scan. TakeOff uses those routes on device to detect countries you may have visited. TakeOff does not write Health data, share HealthKit data with third parties, sell HealthKit data, or use HealthKit data for advertising.

Photo library access is used only for workflows you start, such as attaching photos to trips, adding document scans, scanning receipt images for expense suggestions, or importing visited countries from geotagged photos. Location access is used for location-based travel tools such as coordinates, compass, sunrise/sunset, and nearby context. You can decline these permissions and keep using the rest of the app.

You can change permissions any time in your device’s system settings. You can turn off iCloud Sync, Apple Suggestions, and Spotlight indexing in TakeOff Settings. Revoking Calendar access stops future calendar updates; events already exported to a calendar can be removed in Calendar.

7. Third-party links and live travel data

When you create a trip with a selected country and no manual cover choice, TakeOff searches the first selected country's name on Pexels and, if needed, Wikimedia Commons to choose a destination cover. Opening Find cover photo also searches the first selected country when one is available; your manual searches are sent to the provider you select. Pexels searches use TakeOff's Firebase proxy; Wikimedia Commons searches go directly to Wikimedia. Photo providers also receive ordinary connection information when images load. Automatic searches do not include your trip title, notes, bookings, or documents. The proxy temporarily caches Pexels search results and keeps request counts for usage limits. The chosen photo and its source and license credits are saved with your trip, follow your existing sync settings, and are independent of the temporary search cache. You can replace or remove the cover.

TakeOff may link to external travel services or websites. Those services are governed by their own policies. TakeOff does not share your personal app data with those providers.

To show live travel information, TakeOff fetches data from Apple and third-party providers using non-personal query terms such as country codes, airport codes, flight numbers, and currency codes. Flight schedule, airport, and route-option lookups use TakeOff's Firebase Cloud Functions proxy and AirLabs or Logostream. Requests can include flight numbers, origin/destination airport codes, departure dates, route search limits, and candidate airport paths. The backend uses your anonymous Firebase UID for request quotas; it does not receive trip notes, bookings, documents, or payment details. Airline logos can load from Logostream. Currency rates use Frankfurter or ExchangeRate-API. Map/place searches and weather requests use Apple services and send the location or search information needed for the query. Firebase proxy requests are protected by App Check.

Apple Suggestions

Apple Suggestions is enabled by default on each device. When you open a saved trip or eligible activity, TakeOff contributes its basic title, planned dates and time zones, known place names and coordinates, recorded outcomes, and identifiers that reopen the record in TakeOff. Successfully saved outcome changes can refresh an existing contribution. These activities can inform Siri, Search and, where supported, Journal suggestions. Apple decides what appears; TakeOff cannot inspect or guarantee a recommendation.

Automatic contributions exclude notes, photos, travel documents, known booking references and financial fields. Titles are basic fields you write, so avoid putting private information in titles if you want them included in suggestions. TakeOff keeps a local identifier/fingerprint receipt for cleanup and removes stale contributions after saved changes, deletion or sync while the app runs. Turn off Apple Suggestions in Settings to stop and remove these contributions on that device. This setting is separate from Spotlight indexing in Siri & System Actions.

Write and manage entries directly in Apple Journal. TakeOff does not create, read or synchronize Journal entries and cannot confirm that a suggestion appeared or an entry was saved. Disabling suggestions does not delete entries in Journal. Recap remains a separate, explicitly selected trip export; its photos are resized copies without original photo metadata and originals are not changed.

8. Retention and deletion

Your saved travel records and attachments remain until you delete them. In Tools > Settings > Syncing, Delete All Data removes local travel models, document originals and recognized text, protected shared-file imports, pending action drafts, local caches, and TakeOff notifications. It removes TakeOff's Apple Suggestions contributions on that device and requests removal of the anonymous Firebase identity and its provider quota records. If any part fails, TakeOff reports it so you can retry. It does not cancel an App Store subscription or delete entries you created in Apple Journal or exported to Calendar.

When iCloud sync is active, saved record deletions propagate through CloudKit as devices synchronize. If sync is off, other devices or existing iCloud copies can retain data. Manage those copies through Apple's iCloud storage settings. Removing the app alone does not request deletion of Firebase records or existing iCloud copies; use Delete All Data before uninstalling.

Request-count records linked to your anonymous identifier become eligible for deletion 40 days after their last update and are checked by daily backend cleanup. Public provider results are temporarily cached separately from your personal travel records. Firebase Authentication retains an anonymous identity until it is deleted. Uploaded analytics, crash reports and performance traces are governed by the configured Firebase/Google retention periods and are not erased by deleting the anonymous Auth identity. Delete All Data resets the local Analytics identifier; it does not erase previously uploaded analytics, crash reports or performance traces.

For privacy access, correction, deletion, or consent-withdrawal requests, contact contact@sinuk.dev. Describe the service and approximate dates involved; do not send travel documents or other sensitive records. We will explain which data can be identified and removed, including any applicable retention requirements. You can withdraw device permissions in system settings and stop optional sync or system contributions in TakeOff Settings.

Third-party services handle requests under their own policies: Firebase privacy, Google privacy, Apple privacy, Pexels privacy, and Wikimedia privacy.

9. Changes

This policy may be updated as TakeOff evolves. The date above reflects the latest published version.