Last updated: 5 August 2026
Tripfolk is a meetup app for travellers and locals. This policy explains exactly what we collect, why we collect it, who else sees it, and how to get rid of it. It is written to be read, not to be survived.
The short version. We store the profile you fill in, the trips and plans you create, your messages, and an approximate location. We never store the precise coordinates your phone reports. We do not sell data, we do not run ads, and there are no third-party analytics or tracking SDKs in the app.
Tripfolk is operated by Ali Kaptanoğlu (İstanbul, Türkiye), the data controller for the purposes of the GDPR and Türkiye's KVKK. Contact: privacy@tripfolk.app.
| Data | Why | Legal basis |
|---|---|---|
| Google account: email, name, profile picture | To create and sign you into your account | Contract |
| Profile: display name, date of birth, home country, bio, languages, interests, photos | To show you to other members and check you are 18+ | Contract |
| Approximate location (see §3) | To show travellers near you and put you in a city | Consent (you can refuse or withdraw) |
| Trips: city and dates | To show who else will be there at the same time | Contract |
| Plans and group/direct messages | To run the meetups and conversations you take part in | Contract |
| Countries you mark as visited | Your passport map and shared-country badges | Contract |
| Verification selfie | To confirm you are a real person; deleted right after review | Consent |
| Reports, blocks, moderation decisions | Safety, and to stop banned people coming back | Legitimate interest |
| Device push token, app version, coarse country from IP | Notifications, security, abuse prevention | Legitimate interest |
| Subscription status (if you buy Tripfolk Plus) | To unlock paid features | Contract |
We do not collect your contacts, your photo library beyond the images you pick, your calendar, or your browsing activity. There is no advertising SDK and no third-party analytics in the app.
This is the part most apps gloss over, so here is the mechanism in full.
Your display name, photos, role, home country, bio, languages, interests, verified badge, passport countries and approximate distance are visible to other signed-in members. Your email address, date of birth and precise location are never shown. People you block cannot see you at all, and you cannot see them.
We do not sell or rent personal data to anyone, for any purpose.
Open the app, go to Profile → Settings → Delete account. Your profile is anonymised and your trips, plans, chat memberships, passport entries, location history and sign-in identities are deleted. This cannot be undone. If you cannot access the app, email privacy@tripfolk.app from your registered address.
Depending on where you live, you may have the right to access, correct, export, restrict or erase your data, to object to processing, and to withdraw consent. Write to privacy@tripfolk.app and we will respond within 30 days. You may also complain to your local data protection authority (in Türkiye, the KVKK Board).
Tripfolk is for people aged 18 and over. We ask for your date of birth at sign-up and it cannot be changed afterwards. We remove accounts we find to belong to minors. If you believe a minor is using Tripfolk, report the profile in the app or email safety@tripfolk.app.
Traffic is encrypted with TLS. Sign-in tokens are short-lived and refresh tokens rotate — if a refresh token is ever reused, every session for that account is revoked immediately. Location fuzzing is keyed with a secret held only on the server. No system is perfect; if you find a vulnerability, please write to security@tripfolk.app.
Cloudflare processes data on servers around the world, so your data may be handled outside your country. Transfers out of the EEA and UK rely on Standard Contractual Clauses.
If we change this policy in a way that materially affects you, we will tell you in the app before the change takes effect. The date at the top always reflects the current version.