Trip2Art Privacy Policy
Last updated: 2026-09-14
Trip2Art ("we," "us," "the app") turns your own travel photos into a printable coloring book. This policy explains what we collect, why, and what happens to it. We wrote it in plain language on purpose.
Who this app is for
Trip2Art is for adults aged 18 and over. By creating an account you confirm that you are 18 or older.
Upload your own travel photos. We do not screen the content of your photos. The AI providers we use apply their own safety filters, and if one of them declines a photo we will tell you it was declined and delete it — but the decision is theirs, not ours, and we make no promise about which photos will or will not be accepted. You are responsible for having the right to upload the photos you choose.
What we collect
| What | Why | How long we keep it |
|---|---|---|
| Your email address | To create and manage your account | For as long as your account exists |
| Your name, email address and Google account number (only if you sign in with Google) | To sign you in without a password, and to recognise you next time | Your email address and Google account number: for as long as your account exists. Your name is read when you sign in and not stored. See "Signing in with Google" below. |
| The travel photos you upload | To generate your coloring book pages | Deleted within 24 hours of your book being finished — usually within minutes. We do not keep your original photos after that. If you pick photos but don't make your book, we keep them for 20 hours so you can finish it on any device, then delete them — always within 24 hours of picking them. |
| The coloring-book pages we generate, and your finished PDF book | This is the product you're making — it's meant to stay in your library | For as long as your account exists, or until you delete that book |
| Push-notification token (if you allow notifications) | So we can tell you when your book is ready | Until you sign out on that device, or delete your account |
| Reports you submit (using the in-app report button) | So we can review flagged content | For as long as needed to review and act on the report |
| Basic safety/refusal records (e.g., if a photo couldn't be processed) | To keep the service safe and to improve it | Up to 12 months |
| Crash and diagnostic reports (if the app runs into an error) | To find and fix bugs so the app keeps working | 30 days, then deleted automatically. These reports carry nothing that identifies you — no name, no account, no device ID, no IP address. |
| Where your photos were taken (only if your camera saved it into the photo) | To suggest a title for your book, like "Punta Cana · September" | A rounded, town-sized location — never the exact spot — stays with the book for as long as the book does. See "Where your photos say you were" below. |
We do not collect financial information or any advertising identifier, and we use no analytics or advertising SDKs of any kind. We never ask your phone for your location — the app has no location permission and cannot see where you are. But the photos you pick often carry a location of their own, and we'd rather tell you what happens to it than leave you to find out. The section called "Where your photos say you were" explains it in full.
Signing in with Google
You can create an account or sign in with Google instead of a password. If you do, Google tells us three things: your name, your email address, and a number that identifies your Google account. Nothing else. We never see your Google password, and we never send Google your photos, your books, or anything you make here.
We read your name when you sign in, and we do not store it. We keep your email address and the Google account number because you asked us to — they are how we give you the account you signed up for, and how we know it is you next time. If you delete your account, the link to your Google account is deleted with it. You can also remove Trip2Art from your Google Account's settings at any time.
The "Continue with Google" button is ours, and nothing is sent to Google when it appears. Only if you press it does your browser go to Google's own sign-in page, and what happens there — including the ordinary information any website visit sends, such as your IP address — is Google's, under Google's own privacy policy: we do not control it and we do not receive it. If you would rather Google knew nothing about you, create your account with your email address instead. Everything in Trip2Art works the same way either way.
How your photo is actually used
- You pick photos from your own phone using your phone's built-in photo picker — we never ask for full access to your photo library.
- Your photo is uploaded over an encrypted connection and sent to an AI image service to generate a black-and-white coloring-book page from it. We use Replicate, running the open-source Qwen image model. It is the only image service your photo goes to — there is no second one, and if Replicate is unavailable your book waits rather than being sent somewhere else.
- The generated line-art page — never your original photo — is separately reviewed by Anthropic's AI (Claude) to check that it's clean and printable. Anthropic never sees your original photo.
- Once your page (or your whole book) is finished, your original photo is deleted. Our target is minutes; our guaranteed outer limit is 24 hours, backed by an automatic system that deletes anything left over regardless. If you pick photos but don't make your book, we keep them for 20 hours so you can finish it on any device, then delete them — always within 24 hours of picking them.
- Unlike your original photo, the finished black-and-white pages and your PDF book are not deleted after generation — they're the product you made, so they stay in your account until you delete them, and you can re-download and reprint them any time.
Replicate, Anthropic and Google handle this data under their own terms. Anthropic's commercial terms with us include a data-processing agreement. Replicate works under its standard terms of service, and Google's Geocoding service works under Google's own terms.
Where your photos say you were
We never ask your phone for your location. The app requests no location permission, and it cannot see where you are.
Most cameras, though, write the spot into the photo itself. When you pick a photo, that comes along with it. Here is everything we do with it.
We blur it the moment it arrives. As your photos come in we read the location out of them and immediately round it off to about a kilometre. A kilometre is enough to name a town. It is not enough to find a house. The rounded version is the only one we ever store — the exact spot your camera recorded is never written down anywhere in our systems.
We use it to name your book. One rounded point per book goes to Google's Geocoding service, which sends back the name of the place, so your book can call itself "Punta Cana · September" instead of "Untitled". Google gets the rounded point and nothing else — no photo, no email, no account, nothing that says the question came from you. If Google can't name it, or we can't reach them, nothing breaks: you just type your own title.
What we keep, and for how long. The rounded point and the place name sit with your book for as long as the book does, and they go when you delete the book or your account. Separately, we keep a short list of rounded points and the names they map to, so we never pay to ask about the same town twice. Nothing in that list points at you: it is a coordinate and a town name, the same pair any map already prints. It has no account, no book and no photo attached, so we keep it, and deleting your account does not remove it — there would be nothing of yours in it to remove.
The one thing we don't blur. We send your photo to the AI service that draws your page exactly as you gave it to us — we don't edit the file. So if your camera wrote an exact location inside it, that exact location travels inside the photo, and the AI service receives it. Then the photo is deleted on the same 24-hour promise as everything else. If you would rather it never left your phone at all, most phones can remove location from a photo before you share it, and Trip2Art works just as well without it.
Where your data lives
Your photos, your books and your account are stored in Germany — in Amazon Web Services' Frankfurt region (eu-central-1). We would rather name the place than round it off:
- Your photos and your finished pages sit in our storage there: the photos only until your book is done (or for 20 hours, if you pick them and don't finish it), the pages for as long as you keep them.
- Your account records are in our database, in that same region — your email address and account details, the bookkeeping about your books (titles, dates, statuses — never the images themselves), your push-notification token if you allow notifications, and any reports you submit.
- Making a page sends your photo to one of the AI services named above. Both are US companies, so making your page sends your photo outside Germany. We do not promise a specific processing location and you should not read one into this.
- Emails we send you — such as the link that confirms your email address, the note that your book is ready, or a reminder before an unfinished book is deleted — go through Resend, an email service in the United States. Resend receives your email address and the message, and keeps a copy of the emails it sends for us. It works under a data-processing agreement that is part of its terms with us.
We are a United States company, and we keep your photos, books and account in Germany. If you are in the United States, they are sent to and stored in the European Union. In the other direction: making a page sends your photo to AI services run by US companies, so at that moment your photo leaves Germany, and it is deleted afterwards on the same 24-hour promise as everything else. The emails we send you go through Resend, in the United States.
Crash and diagnostic reports
When something in the app goes wrong, it can send us a short crash report so we can find the bug and fix it. A report is plain technical text: the error message, a technical stack trace (the internal trail that shows a developer where the error happened), the name of the screen it happened on, the app version, and which kind of device it was running on. That is the whole of it.
A crash report carries nothing that identifies you. We do not store a name, an email, an account link, a device ID, or an IP address with it — so we can see that a bug happened, but not who it happened to. If an error message happens to pick up anything that looks like photo data, that part is stripped out before the report is saved. We keep these reports for 30 days and then delete them automatically.
These diagnostics are entirely first-party: they go only to our own systems, under our own rules. We do not use any third-party crash-reporting or analytics service, and our build is set up to keep those out — a check fails the build if such a tool is ever added.
What we count
We count two things, and this is all of it: how many times the front page was opened, and how many accounts were created. Each is a single number per day.
There is nothing in those numbers about you. No cookie is set. No identifier is created, stored or hashed. The counts do not include your IP address or your browser's user-agent string, and they are not a record of visits — a day's traffic is one integer, so there is nothing in it to link back to a person, by us or by anybody else. Our security logs are separate, and are described below.
We do separate the front page's number into "people" and "automated", because search engines and link previewers open the page too and a single number would mostly be measuring them. To do that we look at the user-agent string your browser sends, decide which of the two counters to add one to, and then discard it. The counters do not store it.
We count these because we would otherwise have no idea whether the page works at all, and the usual way to find out — an analytics service and a cookie — would make the promises above untrue.
Security logs
Our servers keep a log of each request they receive: your IP address, the address (URL) you asked for, the time, and the user-agent string your browser or app sends. We use these logs to keep the service secure, to stop abuse, and to find and fix problems. They are stored in Frankfurt and deleted automatically after 30 days. Our firewall also keeps the same details for each request it blocks, for 7 days.
What we never do
- We never show you ads, and we never let anyone else show you ads in this app.
- We never use third-party analytics or tracking SDKs. The only measurement we do is the two daily counts described above, and nothing in them identifies anyone.
- We never sell your photos, your data, or access to either.
- We never share your original photo with anyone except the AI service that draws your page — Replicate, and only Replicate — and never for anything but making your coloring book.
- We never ask your phone for your location, and we never store the exact spot a photo was taken.
- Where your data lives is stated plainly above, under "Where your data lives", rather than left unsaid.
- We never send crash or diagnostic reports to a third-party crash-reporting or analytics service — the diagnostics we collect stay first-party, and our build blocks those tools from ever being added.
Children's privacy
Trip2Art is not directed at children, has no child accounts, no child login, and no part of the app is designed for a child to use directly. Accounts are only for adults aged 18 and over. We do not knowingly collect personal information from children under 13. We do not screen the content of uploaded photographs — our AI providers apply their own filters and may decline a photo, but we make no claim to detect what a photo contains.
The photos you upload may show your children. We handle them like every other photo:
- Your original photo is deleted once its page has been drawn — usually within minutes, and always within 24 hours of your book being finished. Photos you pick for a book you don't finish are deleted after 20 hours — always within 24 hours of picking them.
- The pages made from it stay in your library until you delete the book or your account.
- We do not use your photos, or the pages made from them, to train AI models.
- You can report any page from inside the app, with the report button on that page.
If you believe a child has created an account, tell us at privacy@trip2art.com.
Your choices and rights
- Delete your account: in the app, under Settings, or at trip2art.com/public/delete. Deleting your account removes your books, your photos (if any remain in transit), and your account data, typically within 24 hours. A book you have not finished, and its photos, are deleted at once.
- Delete a single book: from your library, at any time.
- Book reminders: if you leave a book unfinished, we email you once, about six hours before its photos are deleted. Turn this off in the app under Settings, or with the link in that email.
- Report content: every generated page has a report/flag button that sends a report directly to us.
- Ask us questions: contact us at privacy@trip2art.com.
Security
Your photo is sent over an encrypted (HTTPS) connection to the AI provider that generates your page. Our own photo and book storage runs in Amazon Web Services' eu-central-1 region, in Frankfurt.
Changes to this policy
If we change what we collect or how we use it — especially anything about photo processing — we will update this page before the change ships in the app, not after.
Contact us
Trip2Art is run by TheBloomsbridge LLC, a Florida limited liability company. It is the company responsible for your personal information under data-protection law.
Trip2Art · support@trip2art.com · privacy@trip2art.com
Child-safety concerns: childsafety@trip2art.com