Joru
PRIVACY POLICY
Legal · Privacy

Privacy Policy

Joru is a travel planner whose AI runs on your device. This policy explains what data the app handles, what stays on your phone, what leaves it and why, and the controls you have. Plain language first, details below.

Last updated: 9 August 2026 · Applies to the Joru app for Android and iOS

The short version

Who we are

Data controller

Joru is developed and published by Raúl Corvo Uña, NIF 48335156N — Av. Maisonnave 41, 3.º B, 03003 Alicante, España. For any privacy question or data request: corvo.ai.studio@gmail.com. Joru is operated by an individual developer based in Spain (EU).

What the app handles

Data you enter, kept on your device

To build a plan, Joru uses the details you provide in the trip form and while using the app. These are stored locally on your device and are not sent anywhere unless you explicitly enable sync (see below):

Joru does not require an account to plan trips, and does not ask for your name, phone number or contacts.

Facts & connectivity

Open-data services the app contacts

Joru is not an “offline” app: to keep every place, guide and forecast real, it fetches facts from open data over the network. To do that it sends the destination or map area (a place name, a search query or coordinates) to the services below. It does not send your saved trips, traveler details, budget or other personal preferences to them. As with any web request, these services receive your device's IP address and process it under their own policies.

Map data © OpenStreetMap contributors (ODbL); guides from Wikivoyage (CC BY-SA); forecasts from Open-Meteo. The AI model runs locally on your device — your preferences and itinerary are never sent to a cloud AI provider.

Optional features

Sign-in, sync, analytics and purchases

These features send data off your device, so each is optional and, where required, asks for your consent.

Sync with your own cloud Optional

If you turn on sync, Joru saves a copy of your trips to your own cloud storageGoogle Drive on Android, iCloud on iOS. Never to a server of ours: we have no backend and never receive a copy of your trips.

In both cases the snapshot is encrypted before upload.

Sign-in Optional

Signing in is only used to enable sync, and only with the provider for your platform: Google Sign-in on Android and Sign in with Apple on iOS. Joru receives a basic account identifier and an authorization token for the storage; it does not post anything to your account or read your other data. Sign in with Apple lets you hide your email address if you prefer.

Crash reports & usage analytics Firebase

Joru uses Google Firebase for two separate things, with two separate controls in Settings:

Neither uses your advertising ID. The app also uses Firebase Remote Config to adjust settings (such as the on-device model), which does not require personal data.

On iOS, if you turn usage analytics on, the system's App Tracking Transparency prompt is shown first — and only then; if you leave analytics off, Joru never asks. Joru does not track you across other apps or websites in any case.

Premium purchases Optional

Premium (a monthly subscription or a one-time purchase — what each covers is set out in the Terms of Use) is handled by the store you installed from — Google Play Billing on Android, the Apple App Store on iOS — together with RevenueCat, which unlocks your entitlement across your devices. RevenueCat receives an anonymous app-user identifier and the purchase token; we never receive your payment card details — those are handled entirely by Google or Apple.

Booking links

Affiliate links

Once your plan is ready, Joru may show links to trusted travel partners (for stays, tours & tickets, car rental, airport transfers, eSIM data, travel insurance, trains & buses). These are clearly labeled as “affiliate link”. There is no advertising SDK and no tracking before you click. If you choose to open one, the partner's website may set its own cookies and identifiers under its own privacy policy, and we may earn a small commission at no extra cost to you — which keeps the free version free. Partners are reached through networks such as Travelpayouts, Impact and Amazon Associates.

At a glance

Data summary

DataWhyWhere it livesBasis
Trip details & preferencesBuild your itineraryOn your deviceProviding the service
Destination / map queriesFetch real places, weather, mapsSent to open-data servicesProviding the service
Region nameDownload the offline map extractSent to GitHub; file cached on deviceProviding the service
Trips backupSync across your devicesYour own Google Drive or iCloud (encrypted)Your consent
Account tokenEnable syncDevice secure storageYour consent
Crash reportsFix bugs, keep app stableFirebase CrashlyticsLegitimate interest (opt-out)
Usage analyticsImprove the appFirebase (if enabled)Your consent (opt-in)
Purchase tokenUnlock PremiumGoogle Play or App Store, & RevenueCatProviding the service
Your rights (GDPR)

Control and legal bases

Joru is built in the EU and follows the GDPR. Our legal bases are: performance of the service for core planning; your consent for sync and usage analytics (which you can withdraw at any time); and legitimate interest for crash reports, which keep the app stable and which you can turn off in Settings. We follow data minimization — we don't collect more than a feature needs.

There is no automated decision-making that produces legal or similarly significant effects about you: the on-device AI arranges a travel itinerary, nothing more. We do not sell personal data, and we do not build advertising profiles.

You can exercise your rights directly in the app, without contacting anyone:

You may also contact corvo.ai.studio@gmail.com for any request. If you are unhappy with how we handle it, you have the right to lodge a complaint with your local data protection authority — in Spain, the Agencia Española de Protección de Datos (aepd.es).

Retention & security

How long, and how it's protected

Snapshots are encrypted before upload, access tokens are stored in the device's secure keystore, and all network traffic uses HTTPS. Some services above (Google/Firebase, RevenueCat, Stadia Maps, GitHub and the open-data providers) may process requests on servers outside the EU. Those transfers rely on the providers' own safeguards — an adequacy decision (such as the EU–US Data Privacy Framework) or the European Commission's Standard Contractual Clauses. Each provider is an independent controller of the request data it receives, under its own privacy policy.

Children

Not directed to children

Joru is a general-audience travel planner and is not directed to children. You may enter children's ages when planning a family trip; this is used only to tailor the itinerary, stays on your device, and is never used to profile a minor or for advertising.

AI transparency

Plans are AI-generated

Itineraries are drafted by an on-device AI model, which arranges and describes real candidates from open data. Plans may contain errors and are not professional travel advice — please verify opening hours, prices and availability before you travel.

Updates

Changes to this policy

If this policy changes, we'll update the date at the top and, for significant changes, note it in the app. Continued use after an update means you accept the revised policy.