← Back to home Terms of Service →

Privacy Policy

Eurica is a trip planner built and run by one person, Lorenzo Piccolo, from Italy. This page says what the app stores, where, for how long, who can see it, and what it does not do. It is written to be read, not to cover anyone. If something here is unclear, write to lorenzopikkolo@gmail.com.

1. Who is responsible

The person responsible for your data (the “controller” under Regulation (EU) 2016/679, the GDPR) is Lorenzo Piccolo, a private individual. Eurica is not a company and has no staff. Contact for anything about your data: lorenzopikkolo@gmail.com.

On what grounds. Your account, and everything you put into a trip, are handled in order to give you the service you signed up for: that is a contract, Article 6(1)(b) of the GDPR. Counting visits on the public pages, and the measures that keep the service standing up — rate limits on the sign-in form, server logs — rest on legitimate interest, Article 6(1)(f). Nothing here runs on consent, because nothing here is optional decoration. You are never profiled, and no decision about you is made automatically.

2. What is stored

Only what you type or upload, plus what is needed to keep the service running.

3. Where it is stored

The database, authentication and file storage run on Supabase, and the application on Vercel. Both are configured in the Frankfurt region (fra1), in the European Union. Maps are drawn by Mapbox: when you open a map, your browser requests map tiles and place searches from Mapbox directly, so Mapbox sees your IP address and the places you search. Fonts are served by Eurica itself, from this domain: opening a page does not announce you to anyone. Signing in with Google involves Google, but only if you choose that button.

Leaving the European Union. Supabase and Vercel are United States companies. Your data sits in Frankfurt, but their staff can reach it from outside the EU when they run or repair the platform. Supabase’s data processing terms carry the European Commission’s Standard Contractual Clauses, and those terms apply to every account, including free ones. Vercel’s equivalent terms cover its paid plans only, and Eurica runs on the free one — so for the hosting layer that formal agreement is not in place. It is written here rather than left out, which is the same rule the rest of this page follows.

No data is sold, and nothing is shared with anyone for advertising or marketing. There is no advertising anywhere in Eurica.

4. How files are protected, and what that does not mean

Uploaded files sit in private storage buckets. They are never reachable by a public URL: the app hands out a temporary signed link, valid for a few minutes, only after checking that you are allowed to see that file. The storage provider encrypts files at rest.

This is not end-to-end encryption. The encryption key belongs to the provider, not to you. In practice it means that a stolen disk is useless, but anyone with administrative access to the Supabase project can read the files and the database. Today that is one person: the administrator of this instance (see section 8). If you need a file that nobody but you can ever open, this app is not the right place for it.

5. Identity documents are not what this app is for

Eurica is meant for tickets, boarding passes, booking confirmations and travel insurance. It is not designed to hold passports, ID cards or driving licences. Airlines and hotels ask for the document number, not a scan, and a scan stored here is one more copy that could be exposed if your account or a shared trip is compromised. The app warns you when a file name looks like an identity document, and lets you decide. If you upload one anyway, it is treated like any other file: private bucket, temporary links, no extra protection.

6. Sharing a trip

When you share a trip, the people you share it with see its itinerary. By default they do not get access to the attached files (ticket PDFs and documents) unless they have editor permission or you switch on “Share attached files with viewers” for that trip. Invite links expire after 30 days and can be revoked from the trip’s sharing panel at any time; until then, anyone who has the link can use it. Files attached to your reminders stay in your own space unless you can edit the trip they belong to. As the trip owner you can also lock a single file (a ticket PDF or a document): a locked file opens only for you, not for editors or viewers, whatever the trip’s sharing settings.

7. How long data is kept

For as long as your account exists, with one exception: ticket PDFs attached to a stop are deleted automatically 60 days after the trip’s end date. A ticket is useless after the trip, but it still carries your booking reference and name, so it does not stay around. The app shows the deletion date on the trip and on the stop from the day the trip ends; download what you want to keep before then. Every other file — documents attached to a trip, things in “Always with you”, reminder attachments — is kept until you remove it. You can also give any of them a deletion date of your own, from the file’s menu in the Archive: sixty days after the trip, in six months, in a year, or never. The date is shown on the file, and nothing is deleted on a schedule you did not choose. Never is the default, because a passport scan you keep on purpose should not quietly disappear.

When you delete your account, everything you own (trips, days, stops, files, reminders, shares, invite links, profile picture) is removed immediately by the app itself, not by a queue. The providers may keep copies in their backups for a limited period after that. Files you uploaded into someone else’s trip stay with that trip: they belong to that trip’s owner.

8. Who can see your data

9. Your rights

You can see and change your data in the app. You can delete your account, and everything in it, from your profile settings, without asking anyone. For anything else that the GDPR gives you (access, rectification, erasure, restriction, portability, objection), write to lorenzopikkolo@gmail.com. You can also complain to the Italian Data Protection Authority (garanteprivacy.it).

10. Cookies and visitor statistics

Eurica sets no cookies. Your session tokens and preferences are kept in your browser’s localStorage, which is needed for the app to work and is cleared when you sign out or clear site data. There are no profiling or marketing cookies.

The public pages — the home page, the guides, the sign-in and the legal pages — count visits with Vercel Web Analytics. It is cookieless: it sets nothing on your device and reads nothing from it. Each page view records the time, the page address, where you came from, an approximate location from your connection, and the kind of browser and device. Visitors are counted using a value derived from the request itself, which is discarded after 24 hours, so there is no way to follow you from one day to the next or across other websites. Your IP address is not stored.

The app itself is not measured. Everything behind sign-in — your trips, days, stops, files and reminders — carries no analytics script at all. Nothing you do inside a trip is counted or sent anywhere.

11. What is not claimed

Eurica has no security certification, no audit by a third party and no compliance seal. The security measures in place are the ones described on this page. If that changes, this page will say so.

12. Changes

If this policy changes in a way that matters, you will see it in the app. The date at the top tells you when it was last touched.