Legal
Privacy Policy
Last updated: July 25, 2026
Who we are
Sujova ("Sujova", "we", "us") is operated by EiCapp, based in Finland, Business Address available upon request. Our website is https://sujova.com. We act as the data controller for personal data processed through the service.
Data we collect
- Account email and authentication identifiers
- Profile / display name
- Trip content you enter (destinations, notes, preferences)
- AI-generated itineraries linked to your account
- Trip Alignment group and participant answers stored in our database when you or a person you invited submits them through a shareable Trip Alignment link
- Email addresses of collaborators you invite
- Support messages you submit through /help
- Privacy-friendly analytics events (page views, feature usage)
- A minimal first-party product activity record that Sujova stores in its own backend, consisting of your account identifier, one of a small set of event types (such as opening a trip, adding or editing an itinerary item, reordering or removing an itinerary item, applying a refinement, creating a Trip Alignment group, showing a paywall, or starting checkout), a timestamp, and, where relevant, a reference to the trip. This record never contains your destination, trip description, itinerary text, prompts, comments, personal notes, or Trip Alignment answers
- Payment / subscription status received from our payment processor
- Product feedback you submit through the in-app feedback launcher, including the message text, the category you choose, an optional sentiment, the interface language, a normalized page-context identifier, and (only if you tick the contact-permission box as an anonymous submitter) an optional contact email
- For signed-in feedback submissions, an association between the feedback record and your account identifier. Your account email is not copied into the feedback record.
- The normalized page-context identifier is a short, allow-listed label such as
home,trip_planoralignment_participant. It does not include raw URLs, query strings, trip IDs, group IDs, invite tokens or Trip Alignment participant tokens.
Why we use it
- Create and secure your account
- Generate, save, and adapt itineraries
- Enable trip sharing and collaboration
- Process subscriptions and unlock paid features
- Provide customer support
- Understand product usage in aggregate to improve Sujova
- Operate and improve product features at the account level using first-party activity records
- Send timely lifecycle emails (planning review, pre-departure, and post-trip follow-up) at the appropriate stage of a trip
- Protect the service against abuse and fraud
- Comply with legal obligations
- Review product feedback to identify problems and confusing experiences
- Evaluate feature requests and other suggested improvements
- Respond to a submitter only when they have granted contact permission
Product feedback and abuse prevention
When you submit product feedback, Sujova transiently processes your IP address to derive a one-way hashed identifier used solely for abuse prevention. The raw IP address is not retained in the product-feedback database. The hashed identifier is stored separately in a short-lived rate-limit log and removed automatically after 48 hours. Hashing reduces linkability but does not by itself make the identifier anonymous, and this statement is limited to what Sujova stores in the product-feedback database. Hosting infrastructure may still process request metadata elsewhere in the ordinary course of operating the service.
If you submit feedback anonymously, an optional contact email is stored only when you tick the contact-permission box and choose to provide it. A one-way hash of that email may also be stored temporarily in the same short-lived rate-limit log for abuse prevention, on the same 48-hour terms.
If you submit feedback while signed in, the feedback record is linked to your account identifier. Sujova administrators may retrieve your current account email only when you granted contact permission for that submission. Administrators may also record an internal status, priority and notes to help triage the feedback queue.
Legal bases
We rely on the following legal bases, depending on the activity:
- Performance of a contract (providing the service you signed up for)
- Legitimate interests (security, abuse prevention, product improvement)
- Consent (where required, e.g. optional communications, and your contact permission when you submit product feedback and choose to be reachable about it)
- Legal obligation (tax, accounting, lawful requests)
Third-party services and processors
Sujova relies on the following external services. The role of each is described so you can see what data reaches which provider. Not every provider is a data processor in the strict legal sense; some are service providers or connectivity endpoints. Processing by each provider is subject to that provider's applicable privacy terms.
Supabase and Lovable Cloud
Supabase and Lovable Cloud provide authentication, application hosting, and our database. Account and profile information, trip and itinerary content, collaboration data, notifications, product feedback, and Trip Alignment group and participant responses are stored here.
Paddle
Paddle acts as our merchant of record and payment provider. Paddle handles purchases, subscription billing, applicable taxes, payment information, refunds, and related transaction administration. Paddle's own privacy terms apply to the payment details you submit at checkout.
Resend
Resend sends the transactional email Sujova generates from within the application. This includes collaboration invitations, the welcome email after signup, and support messages and replies. Resend is not used for marketing campaigns.
Loops
Loops receives onboarding and lifecycle email contacts after you sign up. Sujova sends your account email, user identifier, selected language, and a fixed "app-signup" source value to Loops. Sujova does not send Trip Brief answers, Trip Alignment answers, trip descriptions, personal travel notes, itinerary content, or anonymous visitor information to Loops.
In addition, once Sujova activates its trip lifecycle email feature, Sujova may send Loops your account identifier together with one of a small number of derived lifecycle-stage signals — a planning-review stage, a pre-departure stage, or a post-trip follow-up stage — so Loops can deliver the relevant email at the appropriate time. The lifecycle signal is derived from your trip dates and the relevant stage only; Sujova does not send your destination, trip description, itinerary content, personal notes, Trip Alignment answers, or any other trip details to Loops as part of a lifecycle signal. Until this feature is activated, no lifecycle-stage signals are sent.
Plausible
Plausible provides privacy-friendly, cookieless product analytics. Sujova uses it to measure page views, feature usage, funnel progress, and similar product events. Sujova's Plausible setup does not set analytics cookies or persistent visitor identifiers. Custom-event properties are restricted to an approved list of categories and status values. Emails, names, trip descriptions, questionnaire answers, and other directly identifying content are not included in Plausible event properties.
This Plausible analytics is separate from the first-party, account-linked product activity records Sujova stores in its own backend, which are described in their own section below.
Open-Meteo
Open-Meteo provides weather forecasts and destination geocoding for trip planning. Requests to Open-Meteo may include a destination name, coordinates derived from it, and relevant travel dates. Sujova does not intentionally send your account email, user identifier, personal travel notes, or full trip descriptions to Open-Meteo.
Google Maps Platform
Google Maps Platform is used for route calculation and geographic sequencing of itinerary stops. When this feature runs, Sujova sends short place or location strings from the generated itinerary, such as a city name or named public venue, together with the travel mode. Sujova does not send your full trip description, account email, user identifier, or personal travel notes to Google for this routing feature.
This routing feature does not use GPS or continuous device location and does not use Places search. Route requests are made from Sujova's servers through a connector gateway. Google and the connector provider may process technical information necessary to provide the service. Google processes information it receives according to the Google Privacy Policy.
Sujova is designed to exclude private residential addresses from this routing feature. If a location cannot be safely treated as a public travel place, route optimization is skipped and the itinerary continues without it.
Lovable AI Gateway (using a Google Gemini model)
Lovable AI Gateway, using a Google Gemini model, generates and adapts itineraries. When you generate, optimize, enhance, or reroute an itinerary, Sujova sends the AI service the categories of information needed for the task, which may include your trip description, destination, travel dates, language, timezone, traveler preferences, personal travel notes or preferences you have entered, and existing activity titles or notes when the request involves editing an existing itinerary. The AI prompt does not intentionally contain your account email or internal user identifier. Trip descriptions and personal notes are free-text fields. If you include names, contact details, health-related needs, or other personal information in those fields, that information may also be processed by the itinerary-generation services. Processing by Lovable AI Gateway and by Google is subject to those providers' applicable privacy and service terms.
First-party product activity
Sujova keeps a minimal first-party record of certain account-linked product actions in its own backend. This is separate from the cookieless, aggregate Plausible analytics described above. Each record contains your account identifier, one of a small set of event types — such as opening a trip, adding, editing, reordering or removing an itinerary item, applying a refinement, creating a Trip Alignment group, encountering a paywall, or starting checkout — a timestamp, and, where relevant, a reference to the trip. It does not contain your destination, trip description, itinerary content, AI prompts, comments, personal notes, or Trip Alignment answers.
Sujova uses these records to operate and improve the product at the account level — for example to understand feature usage, detect issues, and protect the service. Because they are linked to your account, these records are retained with your account data and are not part of Plausible's aggregate, cookieless measurement.
Browser storage and analytics
Sujova uses first-party browser storage on your device to support product features and continuity, rather than for cross-site advertising.
Session storage and local storage in your browser hold: Trip Brief drafts, individual Trip Alignment drafts, Trip Alignment participant form drafts, the trip idea from the homepage before you sign in, checkout intent while returning from payment, a funnel-source label used in our analytics, per-session dedup markers so the same event is not counted twice, and a per-account marker used to avoid re-sending the onboarding-sync request.
This storage is first-party application storage. Our Plausible analytics setup is cookieless. Sujova does not use advertising cookies or cross-site advertising trackers.
Browser drafts are normally cleared automatically after successful use. They may otherwise remain on your device until the application clears them, you clear them, or you remove them through your browser's storage controls.
Pre-account and anonymous information
Sujova has several entry points that a visitor can use before signing up. Each is handled as follows.
Homepage trip idea. The trip idea you type on the home page is kept in your browser's session storage. It is only sent to our itinerary generation service after you sign in and continue with the request.
Trip Brief. The answers you provide to the Five-Minute Trip Brief stay in your browser's local storage until you sign in and choose to continue. Trip Brief does not ask for or store an email address before signup, and its answers are not sent to Loops or Resend.
Individual Trip Alignment questionnaire. When you fill in the individual questionnaire without yet creating a comparison group, your draft answers stay in your browser's local storage until you sign in and create an authenticated group.
Trip Alignment participant responses. A person invited through a shareable Trip Alignment link can submit answers without creating an account. These answers are stored in Sujova's database and associated with the relevant comparison group. The submission does not require or store a participant email address. The default expiration for a Trip Alignment group is 60 days from creation. After the group expires, the group and its participant answers are removed through Sujova's scheduled cleanup process.
Product feedback. If you submit product feedback without signing in, you may optionally provide a contact email as described in the "Product feedback and abuse prevention" section above.
Data retention
We retain account and trip data for as long as your account is active. First-party product activity records are retained with your account data for as long as your account is active. Support messages are kept as long as needed for support and legal purposes. Payment records are retained by Paddle in line with their own retention obligations. Analytics data is aggregated in Plausible and does not identify you individually. You can request deletion of your account at any time via /help.
Product feedback marked as resolved or dismissed is deleted automatically 12 months after resolution. All product feedback is deleted automatically no later than 18 months after submission. Records in the separate rate-limit log described above are deleted automatically after 48 hours.
Trip Brief drafts, individual Trip Alignment drafts, and other browser drafts on your device remain until they are used successfully, cleared by the application, or removed through your browser's storage controls. Trip Alignment groups and their participant answers are removed as part of the group's expiration and cleanup process described above. These service providers retain and process information according to their applicable terms, privacy policies, service configurations, and agreements with Sujova. Where applicable, Sujova requires service providers to protect personal data and process it only for authorized purposes.
Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
- Lodge a complaint with your local supervisory authority
To exercise any of these rights, contact us through the in-app support page.
Security
We use reasonable technical and organizational measures, including encryption in transit, access controls, and audit logging, to protect personal data. No system is perfectly secure, and we cannot guarantee absolute security.
Contact
For privacy questions or data requests, please use our in-app support form.