Privacy Policy — viaggIA
1. Data Controller
The Data Controller responsible for personal data processed through the viaggIA mobile and web application (available at viaggia.vcuria.app, Google Play Store, and Apple App Store) is:
Vincenzo Curia (VC DEV)
Tax Code: CRUVCN86B02D005U — Via Fortuno SNC, 87064 Corigliano Rossano (CS), Italy
Contact email for privacy & support: privacy@vcuria.app / support@vcuria.app
2. Data Collected
viaggIA processes the following categories of data:
- Trip Planning & Preference Data: Searched destinations, start and end dates, estimated budget, travel style/vibe, number of participants, and AI-generated trip itineraries.
- User Generated Content (UGC): Travel journal entries, uploaded photos and videos in shared group journals, and custom AI virtual postcard captions.
- Financial Sync Data (SoldIA Integration - Optional): If enabled by the user, travel expense amounts, currencies, and tag identifiers (e.g.,
#Japan2026) synced with SoldIA. - Technical & Device Diagnostic Data: Anonymous device identifiers, device model, operating system version (Android/iOS), IP address, and crash reports strictly used for app stability and performance.
3. Device Permissions Required
To provide core features on Android and iOS, the app may request permission to access:
- Camera: To take photos and videos for the group travel journal or AI postcards.
- Photo Library / Storage: To pick existing photos or save generated postcards and trip reports locally to your device.
- Network Access (Internet): Required to generate AI itineraries, load maps, and sync group travel journals.
4. Purposes and Legal Basis
- Service Provision (GDPR Art. 6.1.b): AI itinerary generation, group travel journal collaboration, and 3D collectible passport features.
- Expense Syncing with SoldIA (GDPR Art. 6.1.a): Vacation budget tracking performed upon explicit user action.
- App Security & Diagnostics (GDPR Art. 6.1.f): Performance monitoring, fraud prevention, and bug fixes to ensure application stability.
5. Third-Party Service Providers
Services are hosted and supported by verified sub-processors adhering to GDPR and global security standards:
- Google Cloud & Firebase (Google Ireland Ltd / Google LLC): Backend infrastructure, authentication, and secure database hosting.
- Generative AI Services (OpenAI / Google Gemini API): Used for processing itineraries and postcards. Input data is anonymized and not used for model training.
- Map Providers (Google Maps / OpenStreetMap): For visual route rendering.
6. Account & Data Deletion (App Store & Play Store Requirements)
In accordance with Google Play Store and Apple App Store Review Guidelines (Section 5.1.1 v):
- Users can clear local app data and individual trips directly from app settings.
- To request permanent deletion of your account and all associated cloud data, email privacy@vcuria.app with your account details. Requests are processed within 30 days.
7. User Rights & Contact
Under GDPR and applicable privacy regulations, users have the right to access, rectify, port, or request deletion of their data, or lodge a complaint with their local supervisory authority. Contact us at privacy@vcuria.app.