Trips New trip Import
Guide
Language

Continue with Google
← Home

Privacy Policy

Last updated: 16 Jul 2026

Zarparia is an independent, early-access travel itinerary app built and run by one person, referred to here as "the operator" ("we"). This policy explains what the app stores, why, and how you can see or remove it. It covers the whole product, including the optional Google Photos and MCP connector features.

What we store

When you sign in with Google, we store your email address, name, avatar image URL, your Google account identifier (the "sub" claim), your account status, and account timestamps.

Everything you create in the app is stored too: your trips and itineraries — locations, dates, notes and all other trip content — records of who a trip has been shared with, any share links you create, and any feedback you submit through the in-app feedback button.

If you connect the MCP connector (see below), we store the OAuth grants that let an AI assistant reach your trips. The tokens themselves are kept hashed, never in plain text.

Where it lives

Zarparia runs entirely on Cloudflare: the app itself, its database (Cloudflare D1) and any stored files (Cloudflare R2) all sit on Cloudflare's infrastructure. Cloudflare may process data in the EU, UK or US depending on where its network routes a given request; Cloudflare participates in the EU–US Data Privacy Framework for transfers of that kind.

Google processes data when you sign in (Google OAuth), and — only if you choose to connect it — when you pick photos from Google Photos.

We don't use any other third-party processor, and there is no analytics or advertising service reading your data.

Cookies

Zarparia sets three cookies, all of them essential to running the app. This list is the complete disclosure of every cookie we set — there is nothing else, and none of it is tracking or advertising, so no cookie-consent banner is shown.

  • session — keeps you signed in. Set only once you sign in with Google; httpOnly, so no page script can read it.
  • zarparia-lang — remembers whether you're using the app in English or Portuguese (renamed from ui-locale; an older visit's cookie is carried over and re-issued under the new name).
  • zarparia-theme — remembers your light/dark/system theme preference.

Google Photos

Google Photos is an optional feature. If you connect it, Zarparia only ever sees the specific photos you pick yourself through Google's own Photos Picker — it is never given access to your whole library.

Photos you pick are cached in Cloudflare R2 as two versions each (a thumbnail and a larger display copy), organised per trip, so the app can show them without repeatedly calling back to Google.

Deleting a trip removes its cached photos. Deleting your account (see ‘Your rights’ below) removes every cached photo copy across all of your trips.

MCP connector

The MCP connector is an optional feature that lets you connect an AI assistant (for example, Claude) to your trips using the OAuth 2.1 standard, so the assistant can read or edit your itineraries on your behalf.

Access tokens issued through this flow are stored hashed, the same way a password would be — we cannot read the token itself, only verify a request that presents it.

Deleting your account immediately revokes every MCP grant tied to it.

What sharing a trip reveals

You choose who can see or edit each trip, either by inviting a specific person or by turning on a shareable link. Anyone you share a trip with can see everything on that trip — its locations, dates, notes and any photos attached to it.

They don't see anything about your account itself beyond what the trip shows, and they don't see your other trips.

Your rights

You can download a full copy of everything Zarparia holds about you, and permanently delete your account, at any time from the Account page (/account) — no request to us is needed.

Export your data produces a single JSON file containing your profile, your trips, your sharing history, your feedback and your MCP grants.

Delete account is immediate and permanent: it erases your account, your trips, and every cached photo copy straight away. If you own a trip you'd shared with other people, deleting your account deletes that trip for them too — they lose access immediately, not just you. Trips other people shared with you are simply removed from your account; the owner's trip is untouched.

New-account approval

Zarparia is in an early-access beta. New accounts need the operator's manual approval before they can create or view trips — this is an access control to keep the beta small while it's being tested, not a review of what you store.

Backups

We retain backups of the app's data for up to 35 days, after which older backups expire automatically. Backups exist to recover from an operational failure, not as a way to keep data you've deleted: deleting your account removes your data from live storage immediately, and any copy still sitting in an existing backup is purged once that backup expires within the 35-day window.

Contact

Zarparia doesn't have a support email address yet. The way to reach the operator about this policy, or about your data, is the in-app feedback button — the speech-bubble icon in the header, or in the mobile 'More' menu.

Changes to this policy

If this policy changes in a way that matters, we'll update the ‘Last updated’ date at the top of this page. Continuing to use Zarparia after a change means you accept the updated policy.

Trips
Guide
Language
Continue with Google