This Privacy Policy explains how NP Somewhere collects, uses, discloses and retains personal information when people in the United States use the Somewhere travel-planning app and official website. The state privacy rights described here apply when the relevant law applies to us and to the particular processing. We also honor the choices described below where reasonably possible.
1. Business and contact
- Business: NP, trading as NP Somewhere (“we” or the “Company”)
- Representative: Sejong Lee
- Address: Room 402, Sinjeong Villa, 25-22 Jungang-ro 45-gil, Yangcheon-gu, Seoul 08060, Republic of Korea
- Privacy requests: contact@npsomewhere.com
- Business registration number: 545-01-04035
2. Notice at collection: categories, sources and purposes
We collect the following categories from you, your device, invited trip participants, sign-in providers, app marketplaces, RevenueCat and shared pages you ask us to import. We use them to provide the requested features, administer accounts and purchases, protect the Service, respond to you, comply with law, improve performance and provide advertising according to your choices.
- Identifiers: email address, Firebase UID or guest ID, name or nickname, profile image, sign-in provider identifiers, IP address and device or advertising identifiers.
- Customer records and commercial information: subscription product, marketplace, purchase, restoration, expiration and renewal status, receipt-verification records, credits and ad-reward history. App marketplaces process card numbers and original payment information.
- Internet, device and activity information: device and operating system, app version, access times, feature and screen events, diagnostics, Firebase App Check and app-integrity attestations.
- Geolocation: city-level information derived by service providers and, if you grant permission, current device location used to display your position on the map. We do not store the current position in our Firebase database. Saved places may contain coordinates.
- User content: trip dates and places, addresses, notes, preferences, invitations, images, expenses, settlements, receipts, attachments, support messages and Instagram communications.
- AI and import information: prompts, recent conversation, relevant trip details and suggestions; Triple trip code, supported itinerary, notes, expenses and attachments, source-content hash and import status. We do not retain the full source URL.
- Inferences: travel preferences you provide and trip suggestions generated from that input.
- Sensitive personal information where state law defines it: precise device location if enabled, account credentials handled through the sign-in provider, and content you voluntarily place in free-text, receipts or images. We use precise location only for the map feature you request and do not use sensitive information to infer characteristics.
- Selected Sentry error diagnostics (only when a project DSN is configured and a sign-in error or selected operation failure is reported): authentication provider for sign-in errors; feature, operation name, error stage, and diagnostic code for selected operation failures; exception type and sanitized stack trace; app version/platform and operating-system/device diagnostics. Exception messages are replaced with generic text. Reports exclude account IDs, email addresses, trip/expense content, AI prompts, URLs/tokens, request/response bodies or headers, and breadcrumbs. Sentry may automatically associate the connection IP address with a report; whether it stores IP addresses depends on the project's privacy settings. We use reports to diagnose sign-in and selected operation failures and improve service reliability.
Core account information is necessary for account features. AI, current location and personalized advertising are optional. Please do not put health, biometric, government identifier, password or another person’s sensitive information in prompts or notes.
3. How information is used
- Provide accounts, trips, maps, invitations, sharing, collaboration, expenses, settlements, imports, requested AI features, Somewhere Pro, purchase restoration and credits.
- Authenticate users and devices, prevent fraud and duplicate rewards, secure systems, troubleshoot errors and enforce terms.
- Measure and improve features and reliability, and provide support.
- Show and measure ads according to region, consent and device settings. Where required, personalized advertising is used only after the appropriate choice.
- Meet legal duties, preserve records and establish, exercise or defend legal claims.
- Diagnose sign-in failures and maintain service reliability using limited authentication-error diagnostics.
4. AI processing
When you request an AI feature, we send your input and relevant trip details to OpenAI. An itinerary-edit request does not include the tripmate list, expenses or photo files. Place names, language and coordinates may be sent to Google Places for verification. OpenAI API inputs and outputs are not used to train models by default unless we expressly opt in. We do not enable response storage; temporary caches and abuse-monitoring logs may remain under OpenAI’s API terms.
AI output is a planning aid and can be inaccurate. We do not use AI to make a decision that produces legal or similarly significant effects. You decide whether to apply a proposed itinerary change.
5. Disclosure of personal information
We disclose information for business purposes to:
- Google LLC for Firebase Authentication, Firestore, Storage, Cloud Functions, App Check, Google Places, Forms/Drive, analytics and advertising services.
- OpenAI OpCo, LLC for requested AI generation, conversation and itinerary editing.
- RevenueCat, Inc. for subscription status, entitlements, purchase restoration and management links.
- Apple and Google app marketplaces for sign-in, app integrity, payment and subscription services; Meta/Instagram when you contact us there.
- People you invite, based on your trip and expense permissions. A signed-in user who knows an exact UID, including through a QR code, can retrieve that member’s name, email and profile image; there is no general member-directory search.
- Authorities, courts or professional advisers when required by law or needed for legal claims, security or protection of rights.
- Functional Software, Inc. (Sentry), for sign-in and selected-operation error reporting and diagnostics. See the Sentry Data Processing Addendum and subprocessor list.
6. Sale, sharing, targeted advertising and GPC
We do not sell personal information for money and do not operate as a data broker. Personalized-ad processing through an advertising provider may be considered “sharing,” targeted advertising or a sale under some state laws even when no money is paid for the data. Depending on your settings, the categories involved may include identifiers, device/activity information, approximate location and advertising interactions. The recipient category is advertising and analytics providers.
You may opt out using the app’s More → Ad privacy settings option where displayed, Google UMP privacy options, device advertising/tracking settings, or this email link: Do Not Sell or Share My Personal Information. We do not knowingly sell or share personal information of people under 16 without the consent required by law.
This website does not currently conduct advertising-related sale or sharing, so a browser Global Privacy Control signal has no website opt-out to apply. When we detect a legally valid GPC signal in a context where our website engages in covered sale or sharing, we will treat it as an opt-out for that browser and account where we can associate it. Browser GPC does not technically change native-app advertising choices; use the app or email methods above for the app.
7. Retention
- Account, profile, trip, sharing and expense content, mirrored subscription status and credit balance: until account deletion or completion of the purpose.
- AI trip-generation records: 30 days; AI conversation and edit records/results: 24 hours.
- Triple import jobs: 30 days; imported content follows the ordinary trip period.
- Duplicate-bonus, post-deletion restriction and ad-reward verification records: 90 days.
- Invitation token: 24 hours; administrator audit logs: 365 days; Google Analytics user/event data: 2 months.
- Support forms: until resolved; device cache and preferences: until the app or its data is deleted.
- Legal transaction and dispute records: for the period required by applicable law. Korean e-commerce periods for records we actually hold may include 6 months for advertisements, 5 years for contracts, withdrawal, payment and supply, and 3 years for complaints and disputes.
- Sentry error reports: retained for the period configured for the Sentry project, then deleted under Sentry’s retention and deletion terms.
Firebase Authentication deletion from active and backup systems may take up to 180 days. OpenAI temporary caches may last up to 24 hours and standard abuse-monitoring logs up to 30 days, subject to legal or safety exceptions. Independent marketplace and provider records follow their own retention requirements.
8. U.S. state privacy rights
Where the CCPA/CPRA or another applicable U.S. state privacy law provides the right, you may request:
- confirmation of processing and access to or a copy of personal information;
- the categories and specific pieces collected, sources, purposes and recipient categories;
- correction of inaccurate information;
- deletion, subject to legal exceptions;
- data portability in a usable format;
- opt-out of sale, sharing, targeted advertising or qualifying profiling;
- restriction of the use or disclosure of sensitive personal information beyond permitted purposes;
- a list of specific third parties to which data was disclosed where a state law requires it; and
- equal service and no unlawful discrimination for exercising a privacy right.
Send a request to contact@npsomewhere.com and identify your state and requested right. We verify access, correction and deletion requests using information reasonably necessary to match the account. We do not require verification for an opt-out unless needed to prevent fraud. An authorized agent may submit a request with proof of authority; we may still confirm the request with you where law permits.
For requests governed by the CCPA/CPRA, we acknowledge receipt within 10 business days and respond to access, deletion and correction requests within 45 days, with one additional 45-day extension when permitted and explained. We process sale/share opt-outs and sensitive-information limitations as soon as feasible and within 15 business days. Other state-law requests are handled within the applicable statutory period.
If we deny a request and your state gives you an appeal right, reply with “Privacy Appeal” within 60 days and explain the issue. We respond within the period required by your state and tell you how to contact the state attorney general when required.
9. Children
The Service is not directed to children under 14, and we do not knowingly collect their personal information. If we learn that we have done so, we delete it. A parent or guardian may contact us. We do not knowingly sell or share information of minors without the consent required by applicable law.
10. Security and international processing
Sentry sign-in and selected-operation error diagnostics may be processed in the United States or Germany and other Sentry service locations. The project’s configured Sentry region determines the storage location. A connection IP address may be automatically associated with a report; whether Sentry stores IP addresses depends on the project’s privacy settings. Reports are sent over the network only when a sign-in error or selected operation failure is reported and a project DSN is configured; the exact retention period follows project settings. See the Sentry Data Processing Addendum.
We use administrative access controls, least-privilege access, technical restrictions and HTTPS encryption in transit. No system is completely secure. Data is processed in the Republic of Korea, the United States and other service-provider locations. We use provider agreements and safeguards appropriate to the processing and respond to legally required breach notices.
11. Website storage
The website does not use our own behavioral-advertising scripts. It may save language and theme choices in local storage, which you can remove with browser site-data controls. The app may use analytics and advertising SDKs as described above.
12. Changes
This Privacy Policy takes effect on September 28, 2026. We will publish material changes and their effective date here or in the Service and provide any notice or consent required by law.