Privacy policy
Last updated: 2 September 2026 · Applies to the Tripkosh app and tripkosh.com
The short version
- You can browse every guide and blog post without an account.
- We collect the minimum needed to run your account: phone number, your name, and an optional email.
- Documents you lock in the vault are end-to-end encrypted on your device. We store only scrambled data we cannot read — not Tripkosh, not our hosting provider, no one but you.
- We don't sell your data, and we don't show third-party ads.
- You can delete your account and every piece of your data yourself, at any time.
What we collect and why
- Phone number — your sign-in identity. A one-time code is delivered by SMS through our messaging provider (MSG91); they process your number solely to deliver that message.
- Name and optional email — to personalise the app, and (email) for account recovery and sending you your itineraries. Marketing email is separate and strictly opt-in.
- Your travel data — trips, packing checklists, itineraries and document titles you create, stored so the app works across your devices.
- Documents — files you add to the vault. Documents you mark as locked are encrypted on your phone before upload with keys that never leave your device; we cannot open them, and they are never shared with AI services or anyone else.
- Reading your bookings — to fill in your itinerary automatically, booking documents you leave unlocked (tickets, hotel and activity confirmations, insurance certificates, eSIM vouchers) are read by an AI service, OpenAI, under terms that prohibit using your data for training. Before any text is sent we remove card numbers, Aadhaar and passport numbers. You can keep any document out of this entirely by marking it locked, and you can turn a document's extracted details off by locking it later.
- Bookings you send on WhatsApp — if you message a booking to the Tripkosh WhatsApp number from the phone number on your account, we store it in your vault as an unlocked booking and read it exactly as above; WhatsApp (Meta) delivers the message to us under its own terms. Don’t send passports or IDs this way — use the app’s locked vault.
- Anonymous usage of partner links — when you tap a booking link we record that a click happened (which partner, which page) so we can earn our affiliate commission. This is not tied to advertising profiles.
What we don't do
- No selling or renting of personal data.
- No third-party advertising or tracking SDKs in the app.
- No reading of your locked documents — it is technically impossible for us.
Where your data lives
Data is stored on our servers and our database provider (MongoDB Atlas). Traffic is encrypted in transit (HTTPS). Locked documents are additionally end-to-end encrypted as described above.
Your rights and deleting your data
You can correct your name and email in the app (Profile → Account). You can delete your account and all associated data — trips, checklists, itineraries and every document — directly in the app (Profile → Delete my account & data) or by following the steps at tripkosh.com/delete-account. Deletion is immediate and permanent.
Contact
Questions or requests: privacy@tripkosh.com.