Privacy
What Tabi keeps, who else sees any of it, and for how long. In short: only what the app needs to work, no advertising, no analytics, no tracking scripts.
What is kept
- Your account: your name, email address, a picture if you add one, and your password, stored only as a scrypt hash that cannot be turned back into the password. If you use Google sign-in, which Google account is linked.
- Your trips: what you and the people on a trip put in: the plan, stays, flights, costs, payments and spends. Each trip is seen only by the people on it, and people following along never see the money.
- Signed-in devices: the kind of browser and phone (from what your browser reports), when it was last used, and a keyed hash of the network address, so you can see and sign out devices under Account.
- Your location: only while you choose to share it with a trip, and deleted when the share ends.
- Notifications: the phones you turned them on for, and the notifications you were sent (your newest 300), so the bell can show them again.
- A security record: sign-ins, failed sign-ins, password resets and similar events, with a keyed hash of the network address, never a password.
How long
| What | Kept for |
|---|---|
| Your account and trips | Until you delete them (Account → Delete my account, or a trip's settings) |
| A sign-in on a device | Ends 14 days after it was last used, or when you sign out |
| Shared location | Until the share ends |
| Activity on a trip ("who changed what") | 180 days |
| Security record | 90 days |
| Sign-in attempt counts (to stop guessing) | 1 day |
| An account made without an invite whose email was never confirmed | 7 days |
| A demo | 2 hours |
| Backups of the whole database | One a day; the newest three are kept, so anything deleted is gone from them within three days |
Who else sees anything
Tabi does not sell or share data. To work, it uses these services, each sent only what it needs:
- The host (Render) runs the server and stores the database.
- Map images (CARTO, or the map service this server is set up with) are fetched by your browser, so that service sees your network address and which part of the map you are looking at.
- OpenStreetMap (Nominatim and Overpass) is asked by the server to turn a typed street address into a map pin, and to find places near a point. It is told an address or an area about a kilometre across, never who asked or where you are exactly.
- Open-Meteo (weather) and Frankfurter (exchange rates) are asked by the server about places and currencies, never about people.
- Google, only if you choose to sign in with Google.
- Your phone's notification service (Apple, Google, Mozilla or Microsoft) delivers notifications, encrypted on the way.
- An email service sends account emails (confirming your address, resetting a password) and reminder emails, when this server is set up to send email.
- Links you open (maps, flight tracking, restaurant guides, booking sites) take you to those sites; Tabi fetches nothing from them for you.
What the people who run Tabi can see
Whoever runs this server has the database, so in principle they can see everything in it. Day to day they use an admin dashboard inside the app, which opens only with their password and a code from a second device, ends itself after 15 minutes idle, and records everything done with it. It shows what running the service needs, and no more:
- Accounts: name, email, when made, when last signed in, whether the email is confirmed and Google is linked, the trips and roles on each, and whether the account is suspended.
- Trips: number, name, organisers' emails, how many people, when made and last changed, and how many of each kind of thing are on it (for example "12 stays"), never the things themselves.
- Invite codes (who they are for and how often used, not the code itself), notifications (who got one and when, with any amount taken out of the title, never a message's text), backups, and counts of failed sign-ins and limits reached, with no names or addresses.
- Which days each account used the app, kept for 31 days, to count active people per day.
It does not show trip plans, money, payment details, messages, locations or anyone's own budget. From it, the operator can suspend an account (reversible: sign-in is refused and location sharing stops), sign an account out everywhere, and delete an account or a trip (after a dry run, typing it back and a fresh code). They are told by notification whenever the dashboard is opened on their account.
Needs legal review: whether this describes the operator's obligations under the privacy law that applies where it runs (for example the Australian Privacy Principles, or the GDPR for people in Europe), and who the "operator" is in law.
Cookies
Only the ones Tabi needs, none for advertising or analytics:
jt_session: keeps you signed in.jt_csrf: stops other websites sending requests as you.jt_known: remembers that this browser has signed in to your account before, so someone guessing your password elsewhere cannot lock you out. It holds no personal information.jt_oauth: for ten minutes during a Google sign-in.
The app also keeps a copy of your trips on your phone so it works with no signal. Signing out removes it.
Your choices
- See it: Account → Download my data gives you a file of everything kept about your account, as your access stands today: nothing from a trip you were taken off, and no money from a trip you follow.
- Change it: your name, picture, password, notifications and location sharing are all in the app.
- Delete it: Account → Delete my account removes your account, with any trip only you are on. On shared trips, what you added stays for the others with no name against it, and payments stay on the record so the money still adds up.
Needs legal review: this page describes what the software does. It is not a privacy policy in the legal sense, and it makes no promise about lawful basis, data transfers between countries, or response times to requests.