Legal
BibTrip — App Privacy Policy
Last updated · September 24, 2026
BibTrip is an app for Android and iOS, developed and published by CX Soft E.E. (Athens, Greece). This policy covers the app. The website has a separate policy.
What this policy covers
BibTrip is a trip planner for runners. Everything it does works without an account, on your device. An account — Google or Apple sign-in — is optional: it keeps your trips in sync across your phones and opens the Community, where you can share a trip with your friends or with everyone. This policy says, section by section, what stays on your device, what reaches us when you choose an account, who can see what you share, and how to delete all of it.
There is no advertising, we do not sell data, and we do not track what you do in the app.
What stays on your device
Without an account, your trips, races, day-by-day stops, packing lists, personal bests, photos, videos and music, and the recap videos you create are stored only on your device, and nobody at CX Soft E.E. can see them.
With an account the same is true for anything you mark «Only on this phone», for a stop's private notes, and for a stop you mark private — those never leave your phone, even when the rest of the trip is in your account.
Crash reports
Whether or not you have an account, one thing leaves your device: crash reports. We use Google's Firebase Crashlytics to learn when the app crashes. It sends the technical trace of the failure, the app version, your device model and OS version, and an anonymous installation identifier — a random number for that install, not linked to you, your account, or any other app. A minimal signal is also sent each time the app opens, so we know what share of users are crash-free.
These reports contain none of your content — no trip names, no photos, no notes, no finish times. We do not share them with anyone and use them solely to fix bugs.
The map and links
A trip's map draws its tiles from OpenFreeMap (tiles.openfreemap.org), a public map service. Like any web page, that server sees your IP address and which part of the map you look at, and nothing else about you. The pins are placed by your phone's own map service — Google on Android, Apple on iOS — which receives the place names of your stops for that purpose and is governed by your phone's own privacy settings.
Links you tap — a race's website, a hotel or a flight search — open in your browser; from that moment the site you opened applies its own policy. BibTrip adds nothing to those links that identifies you. Some of them — to Booking.com, GetYourGuide and Skyscanner (through Travelpayouts) — carry BibTrip's partner id, so BibTrip may earn a small commission if you book: the partner learns that you came from BibTrip, not who you are, and you pay nothing extra.
Your account
You can sign in with Google or with Apple. Sign-in is handled by Google's Firebase Authentication, which holds your email address and the provider you used. We never copy your email into our database, and Sign in with Apple's «Hide My Email» works. What BibTrip keeps about your account is your user ID, the display name you choose, and the address of your picture if your provider gave one.
With an account, the trips you keep «In my account» are stored in Google Cloud Firestore, in the European Union (multi-region eur3): the trip, its race, its stops (never a stop's private notes), its packing list, and for each photo its caption, time and order. Photos and clips you add to such a trip are uploaded as small copies — a JPEG under 300 KB, a video under 2.5 MB — to our media store on Cloudflare R2, in Western Europe, through our own service at media.bibtrip.app; your phone keeps the originals. All of this exists so that every phone signed into your account shows the same trips. Nothing in your account is shown to anyone else unless you share it (the next two sections).
Signing out asks whether to keep a copy of your trips on the phone. Deleting the account is described under «Deleting your data».
Bookings by email
Optionally, with an account, BibTrip gives you a personal address — trips-<code>@bibtrip.app — so that flight, hotel and train confirmations can land in your trip by themselves. You can forward emails to it by hand, or switch on Gmail's automatic forwarding once. If you switch forwarding on, every email your Gmail receives passes through our server — not only bookings. Because that is a lot to hand over, here is exactly what happens to each email:
Mail that is not a booking — a newsletter, a bank statement, a password reset — is dropped the moment it arrives. It is matched against a few patterns in memory and discarded: it is not read by a person or by an AI model, it is not logged and it is not stored. Our server keeps a technical log with only the sender's domain and whether the email looked like a booking; never an address, a subject or a body.
Mail that looks like a booking is read once by an AI model, Anthropic's Claude, through Anthropic's API, to pull out the booking's fields — the flight or train number, dates, times, places, the booking code, a hotel's name and nights. Under Anthropic's API terms the text is not used to train its models and is deleted by Anthropic within 30 days, kept until then only for abuse detection. The email itself is not stored by us. What we keep, for up to 30 days, is only those fields, until you add the booking to a trip or dismiss it in the app; also a short fingerprint of its references and times, for 90 days, so that a reminder about a booking you already added is not read again.
Who touches the mail. Our address is served by Cloudflare (Email Routing and a Cloudflare Worker, in Cloudflare's network), which receives each email and hands it to our code. We answer Gmail's forwarding confirmation on your behalf, so you do not have to type a code. You can stop all of this at any time from Gmail («Disable forwarding») and by asking the app for a new address, which makes the old one deliver nowhere. If you would rather send us less, use a Gmail filter that forwards only emails containing «booking» or «confirmation».
The app asks for your agreement to exactly this before the setup opens, and asks again if this section ever changes.
The Community
Everything in this section needs an account and happens only when you choose it.
Your profile is public. Your display name, your picture and your @handle can be seen by anyone using BibTrip, and a search index made of the beginnings of your name and of your handle lets other runners find you. Choose a name and a handle you are comfortable with; you can change both in Settings.
Publishing a trip. When you publish, you choose who sees it: your accepted friends, or everyone. What travels is what you see in the preview: the race, the dates, the stops with their public tip and link (never your private notes, never a stop you marked private), the photos you tick — as small copies — and, only if you tick them, your finish time and your reflection. Your name and picture appear on it. You can take a post down at any time, from the post itself or from the trip.
Friends, applause, comments. A friend request is seen only by the two of you. Applause on a post is visible, with your name, to whoever can see the post. Comments can be written only by the trip's owner and their accepted friends, appear with your name, and can be deleted by you or by the trip's owner. An «I'm going» on a race is shown, with your name, to your friends or to everyone — your choice.
Travelling together. When you invite friends to a trip, or accept an invitation, that trip becomes shared: everyone on it sees and can edit its stops, its packing list and the photos each of you adds, and the trip is kept in its owner's account. Your private stops, your private notes and the personal half of your race — bib, goal, time, reflection — stay yours. You can leave at any time; your copy stays on your phone.
Blocking. You can block a runner: you stop seeing them, they can no longer send you requests or comments, and nobody — including them — is told.
Reporting, takedowns and bans
You can report a post or a comment. A report reaches us with your user ID, the item, a reason and any words you add; only we can read it, and the person you reported is never told who reported them. We keep a report for as long as we need it to act on it.
If something breaks the community rules we may take a post down for everyone, or make a runner's account read-only in the Community: they still see what others share and everything on their own phone keeps working, but they cannot post, applaud, comment, add friends or travel together, and their posts are hidden. A ban can be temporary or permanent. If this happens to you, the app tells you the reason, how long it lasts and how to write to us, and you can contest it at support@bibtrip.app. For that we keep a record with the date, the reason and a short note, for as long as the restriction lasts. These decisions follow the EU Digital Services Act (Article 17) on statements of reasons.
Photos, videos and music
You pick photos, videos and audio through your system's own picker, so BibTrip only ever sees the specific files you choose — it has no access to the rest of your library. Recap videos are saved to your device's gallery and PDF exports to its storage. On iOS, saving a finished video asks for add-only access to your Photos library — BibTrip can add the video, but cannot see or read your existing photos.
The only photos and clips that leave your device are those you add to a trip kept in your account, or tick when you publish — as the small copies described above.
When you add several photos to a trip at once, BibTrip places each one by when it was taken and, if the photo carries it, where. On Android the photo picker asks you first whether to include the photos' location; if you choose not to, only the time is used. To name the place of a new stop, the coordinates of that group of photos are sent to your phone's own map service — Google on Android, Apple on iOS — and, on Android, to OpenStreetMap's Overpass service (overpass-api.de). They are used for that one lookup and are not stored, by us or in the stop, which keeps only the place's name.
When you share a trip yourself
Sharing is always something you start. You can share a trip as a file, as a QR code, or share a recap video or PDF through your operating system's share sheet — you choose the app and the recipient, and the transfer goes directly from your device. We are not a party to it and receive nothing. Publishing to the Community is described above.
Permissions
Notifications (Android and iOS) are used only for the race-day reminders you set yourself and for the progress or completion of things you start in the app — creating a recap video or a backup. They are generated on your device; nothing is sent anywhere. Camera (iOS) is used only to scan a QR code when importing a trip from another device; on Android that scan is handled by Google's code scanner, so BibTrip does not ask for camera access there. BibTrip requests network access on Android. It uses it for the crash reports, the map, your account and the Community when you use them, and to open links you tap — never to send your trips or photos anywhere else. The app never asks for your location, contacts, microphone or health data.
Device backups
Your phone's own backup system may include BibTrip's data — on Android, automatic backup copies the database and settings to your Google account (photos and videos are excluded, and a phone-to-phone transfer carries everything); on iOS this follows your iCloud backup settings. Those backups belong to your Google or Apple account and are governed by their terms, not ours — we have no access to them. You can also save a full backup file yourself from Settings → Backup & restore → “Back up everything”, which stays wherever you put it.
Deleting your data
You can delete any trip, race, stop or photo from inside the app; with an account, a deletion made on one phone reaches your other phones. Uninstalling BibTrip removes all of its local data from your device. Copies you exported yourself, and backups held by your Google or Apple account, are deleted where they live — through your file manager or your account's backup settings.
Deleting your account: Settings → «Delete my account» deletes, at once, your profile, your handle, your trips in the account, your posts, comments, applause and friendships, and your photos and clips in the media store; the trips stay on your phone as its own. So that your other phones can learn of deletions, small deletion markers — a trip's identifier and a time, no content — are kept for up to 90 days. If something could not be removed at that moment, the app tells you and tries again. Crash reports are deleted by Firebase after 90 days. For anything that will not delete, email support@bibtrip.app.
Your rights
Under the GDPR you can ask what we hold about you, have it corrected (your name and handle: in Settings), have it erased (the section above), receive it in a portable form (Settings → Backup & restore gives you your trips as a file), and object to how we use it. Write to support@bibtrip.app; we answer within a month. You can also complain to the Hellenic Data Protection Authority, dpa.gr.
We use your data to provide what you asked for — your account and the Community — and, on the basis of our legitimate interest, to keep the app working (crash reports) and the Community safe (moderation). Our processors are Google (Firebase Authentication, Cloud Firestore, Crashlytics), Cloudflare (the media store and media.bibtrip.app; and, if you use bookings by email, the mail routing and the server that reads them), Anthropic (the AI model that reads a forwarded booking, only if you use bookings by email) and OpenFreeMap (map tiles). Google and Apple, as sign-in providers, apply their own policies to the sign-in itself.
Children
BibTrip is not directed at children. Do not create an account if you are under 16; without an account the app collects no personal data from anyone, of any age.
Changes and contact
If this policy changes, the new version appears at this address with a new date. For anything about privacy in BibTrip, email support@bibtrip.app. For the company, hello@cxsoft.dev.