Legal

Privacy Policy

Effective September 29, 2026

This Privacy Policy explains what information Noxteq ("we", "us") collects when you use noxteq.com and the trip apps built with it, why we collect it, and the choices you have. By using Noxteq, you agree to the practices described here.

1. Information we collect

Account information. When you sign in with Google or create an email/password account (Firebase Authentication), we receive your name, email address, and profile photo.

Trip content. Anything you enter to build a trip — destination, dates, itinerary items, theme choices, custom sections, expenses, and settings info — is stored in our database (Firestore), scoped to your account. A trip you publish becomes visible at its own public link to anyone you share it with.

Device/notification data. If you enable push notifications, we store a device push token (Firebase Cloud Messaging) to deliver reminders for the activities in your itinerary — nothing else about your device is collected for this.

Cookies. We use a single functional session cookie to keep you signed in. No advertising or tracking cookies are set.

2. Payment information

Publishing a trip is a paid, one-time action processed by PayPal. We never see or store your card or PayPal account credentials — PayPal handles the transaction directly, and we only receive confirmation that a payment succeeded, which we record against your trip.

3. Google user data

Connecting your itinerary Sheet or importing bookings from Calendar requires a separate Google consent, distinct from signing in. That consent grants Noxteq exactly three scopes, each used only for the specific feature it enables:

  • drive.file — create and access the one Google Sheet Noxteq creates in your own Drive for a trip. We cannot see or touch any other file in your Drive.
  • spreadsheets — read and write that Sheet's contents, so your itinerary stays in sync between the Sheet and your live trip app.
  • calendar.readonly — read-only access, used only to detect flight and hotel bookings on your Calendar so we can offer to add them to your trip automatically. We never write to your Calendar.

This data is never sold, never used for advertising, and never shared with anyone except as needed to provide the feature you asked for. You can revoke Noxteq's access at any time from your Google Account permissions, which immediately stops any further Sheets or Calendar access.

Noxteq's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. Other services we rely on

A few features call other third-party services directly, none of which receive your account identity: weather (Open-Meteo), currency conversion (Frankfurter), place coordinates (OpenStreetMap Nominatim), hotel photo search (Serper.dev), optional itinerary photos (Unsplash), and the AI trip-planning and theme-design chat features (Anthropic). Where a feature sends your own trip content to one of these (e.g. describing your trip to the AI chat), that content is used only to generate the response you asked for, not to build a profile of you.

Event photos. When you choose a photo from your device for an itinerary event, it is uploaded to ImgBB, a third-party image host, and only the link ImgBB returns is saved with your trip. Before the photo leaves your device it is re-encoded, which strips its location and other embedded metadata, and the upload is made from our servers, so ImgBB never receives your account identity. Anyone who has the photo's link can view it — the same as the rest of a published trip — and ImgBB keeps it until it is deleted there. To have a photo removed, email support@noxteq.com.

5. How we use your information

To operate the service: creating and syncing your trip app, processing a publish payment, sending notifications you've opted into, and preventing abuse (e.g. rate-limiting repeated coupon attempts). We do not use your information for advertising, and we do not sell personal information.

6. Data retention and deletion

We keep your account and trip data for as long as your account exists. You can delete an unpublished trip yourself from its dashboard at any time. To delete your account and all associated data, email support@noxteq.com — we don't yet have a fully self-serve deletion flow, but we'll act on the request promptly.

7. Security

Your trip data is protected by database security rules that only ever let your own signed-in account read or write it (Firestore Security Rules) — this isn't application logic we could accidentally bypass, it's enforced at the database layer itself. Secrets (Google tokens, payment credentials) are stored server-side and never exposed to the browser.

8. Children's privacy

Noxteq is not directed at children under 13, and we do not knowingly collect information from them.

9. Your rights

Depending on where you live, you may have rights to access, correct, or delete your personal information, or to object to certain processing. To exercise any of these, email support@noxteq.com.

10. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by a new effective date at the top of this page.

11. Contact

Questions about this policy or your data: support@noxteq.com.