Valise Privacy Policy

Last Updated: September 20, 2026

Introduction

Valise ("the app") is developed by Grisu Studio. This policy describes what the app stores, what it sends, and what it never touches. Valise has no accounts, no login, no servers of ours and no cloud: a trip is a file in the app's private storage on your device, and it stays there unless you choose to share it. Beyond the ads that keep the app free, the app makes exactly one network request of its own — an optional exchange-rate lookup that you trigger by hand — and everything else it does happens on your phone.

Scope

This privacy policy applies solely to the Valise mobile application.

Data We Collect

Stored on your device only, never transmitted to us: every trip you create and everything in it — its name, dates, base currency and budget; its destinations; the flights, stays, transport, places and notes on the plan with their times, addresses and coordinates; the places you saved on the map; every expense with its amount, currency, category, date, who paid and how it is split; the exchange rates you typed or fetched; the names of the people on the trip; copies of the documents you attached; the cover photo and receipt photos you picked; your settings (language, appearance, sounds, haptics, reminders, default currency); and the answer to the one-time age question as a bracket only — either "under 13" or "13 or over". If you pick a birth year it is converted to that bracket and immediately discarded; the app never stores a date of birth. Collected by Google AdMob, not by us, in order to serve ads: your device advertising identifier (IDFA on iOS, Advertising ID on Android), IP address, coarse device information such as model and operating system version, and ad interaction data. The app never asks for your name, email address, phone number, contacts or account credentials of any kind — there is no account to attach them to and nowhere to send them.

How We Use Your Data

Your trip data is used only inside the app: to lay the plan out by destination and day, to draw the map and the day's route, to work out balances and the fewest transfers that settle them, and to schedule the reminders you asked for. It is never uploaded, never shared and never analysed by us — the app contains no analytics and no crash reporting, and because there is no server of ours there is nowhere for that data to go. Four things touch systems outside the app, each only when you act. The map: on iOS the map is Apple Maps and on Android it is Google Maps, and those map services receive the map viewport you are looking at in order to draw it; searching for a place uses the operating system's own geocoder. Location: tapping "Use my location" on the map asks for location permission at that moment, centres the map once, and stores nothing. Exchange rates: tapping "Fetch today's rates" sends the currency codes on your trip — and nothing else, no identifier of any kind — to api.frankfurter.app, a free public feed of European Central Bank reference rates, and keeps the answer in the trip; rates you type by hand never leave the phone. Sharing: "Share the suitcase" writes a .valise file (the trip data, without the document, cover or receipt bytes) and hands it to the share sheet you chose — AirDrop, a messaging app, mail — and where it goes from there is your choice. Reminders are local notifications raised by your own device; "Add trip to calendar" writes events into the calendar you pick, on tap, and reads nothing else from it. Declining any of the notification, calendar, photo or location permissions keeps the app fully usable — only that one feature does not run. Advertising data is used by Google to deliver and measure ads. In the European Economic Area and the United Kingdom the app shows Google's consent form before any ad loads, and on iOS it shows Apple's App Tracking Transparency prompt behind a short explanation of our own at the first meaningful moment — never at launch. Declining either one keeps ads non-personalised rather than removing them, and you can revisit both choices at any time from Settings → Privacy and ads. The app also caps the content rating of every ad it requests, so gambling, alcohol, dating and similar adult categories are excluded regardless of your consent choices.

Children's Privacy

Valise is a travel-planning tool listed for ages 13 and over and is not directed to children. The app asks one neutral, skippable age question, and keeps the answer as a bracket rather than a date of birth. If you indicate you are under 13, the app switches to child-directed ad treatment on that device: ads are restricted to the "General audiences" rating, are never personalised, no advertising identifier is used, and Apple's tracking prompt is never shown. The setting can be changed at any time in Settings → Privacy and ads, so a parent handing over a phone can tighten it without reinstalling. We do not knowingly collect personal information from children, and the app has no mechanism to do so — there is no account, no messaging and no upload of any kind.

Data Security

Because we run no servers and hold no database of our own, there is no copy of your trips anywhere for us to lose or be compelled to hand over. Your data lives in a SQLite database inside the app's private storage on your device, and the documents and photos you attach are copied into the app's own folder next to it, protected by the operating system's sandboxing and by whatever device encryption you have enabled. You can delete any trip, item or expense from its own screen, "Delete all my data" in Settings erases everything at once, and uninstalling the app permanently removes the database, the documents and the photos with it. A .valise file or a CSV export is written to the app's temporary cache and handed straight to your system share sheet — you decide where it goes, and nothing is uploaded in the process. A .valise file you receive from someone else is merged into your copy of that trip on your device; nothing about it is sent anywhere. Data handled by Google AdMob is governed by Google's own privacy policy at policies.google.com/privacy; the exchange-rate feed is operated by frankfurter.app and receives only currency codes.

Changes to This Privacy Policy

We will update this policy whenever the app's behaviour changes in a way that affects it, and the "Last Updated" date above will change with it. Material changes will also be noted in the app's release notes. Continuing to use the app after an update means you accept the revised policy.

Contact Us

Questions, corrections or a request to delete data: email support@grisu.co with "Valise privacy" in the subject. Because all of your data is held on your own device, a deletion request is fulfilled by deleting the trips in the app, using "Delete all my data" in Settings, or uninstalling — we hold nothing to delete on our side, and we will say so plainly if you ask.

Account and data deletion

How to delete everything Valise holds — and what it holds in the first place.

Company Privacy Policy

For our general company privacy policy, see Grisú Studio.