Campfyr
Legal

Privacy policy

Effective 1 October 2026

The short version. Your trips live on your phone. What syncs through our servers is encrypted on your phone first, with a key only the people in the trip have, so we can’t read it. Your full-size photos are never uploaded to us. We don’t sell data, show ads, or use analytics trackers.

This policy explains how Devian Labs (“we”, “us”) handles information in the Campfyr mobile app and on this website. Campfyr is operated from India. If you have a question, write tosupport@devianlabs.com.

1. What we collect, and why

Your account

You sign in to Campfyr with Google so your trips can sync between the people in them. Through Google Sign-In and Firebase Authentication (a Google service) we receive your Google account’s name, email address and a unique account ID. We use these only to identify you to your trips and to keep your purchases attached to you. You choose the name other people in your trips see.

Your trips

Trip plans, bookings and wallet entries, expenses, members’ names and any UPI ID you choose to add are stored on your phone. To share them with the people in a trip, each change isencrypted on your phone (ChaCha20-Poly1305) with a key that exists only inside that trip’s invite, and then synced through Google Cloud Firestore. Our servers store the encrypted changes and cannot read them.

To let the right people sync a trip, the server also stores, unencrypted: the trip’s random ID, which account created it, which accounts are members, when they joined, and a one-way value derived from the trip key that proves membership without revealing the key.

“Just me” expenses are kept only on your phone and are never synced.

Photos

Photos you add stay on your phone. Small previews and details such as when and where a photo was taken are shared with the people in your trip directly between phones over your local Wi-Fi network (the “campfire”), encrypted with the trip key. Full-size photos travel only phone to phone, when someone asks for one. We do not upload your photos to our servers.

Campfyr reads the location stored inside your photos to group them by place. It does not track your device’s live location.

Purchases

Extra trips are bought through Google Play or the Apple App Store, which handle your payment details; we never see your card or bank information. We store a record of each purchase (its store and order ID) against your account so that what you bought stays yours.

Settling up

When you tap Pay, Campfyr opens a UPI app on your phone with the amount and the other person’s UPI ID filled in. The payment happens entirely in that app; Campfyr does not process, see or store payments.

2. Services that receive some information

To show weather, places and routes, the app sends place names and map coordinates (never your name or account) to these services:

ServiceWhat it receivesWhy
Google (Firebase Auth, Firestore)Account details; encrypted trip changes; membership recordsSign-in and sync
Google Play / Apple App StorePurchase details (handled by the store)Buying extra trips
Open-MeteoCoordinates of the destinationWeather forecasts
OpenStreetMap (Nominatim, routing, map tiles, Overpass)Place names, coordinates, map areasFinding places, road routes, maps, sights along the way
WikipediaDestination name and coordinatesNearby places to visit
Google Maps (opened by you)Stops of a routeNavigation, when you tap Navigate
Anthropic (only if AI planning is offered and you use it)The trip details you choose to send, never photosDrafting a plan or a trip story

These providers process requests under their own privacy policies. Some of them, including Google and Anthropic, may process data outside India.

3. What we don’t do

  • We don’t sell or rent your personal data.
  • We don’t show ads or use advertising identifiers.
  • We don’t use third-party analytics or tracking in the app or on this website.
  • This website sets no cookies.

4. How long we keep it

  • Encrypted trip data stays in the cloud until the trip’s creator deletes the trip.
  • When you leave a trip, your membership is removed; what others already have on their phones stays with them.
  • Your account and purchase records stay until you delete your account.
  • Everything on your phone is removed when you delete a trip or uninstall the app.

5. Your choices and rights

You can view and change your trip data in the app at any time, delete trips you created, and leave trips you joined. You can ask us to access, correct or delete your personal data, or withdraw your consent, as provided under India’s Digital Personal Data Protection Act, 2023 and other laws that apply to you. To delete your account, follow the steps on our account deletion page.

For any privacy request or grievance, contact us atsupport@devianlabs.com. We aim to respond within 30 days.

6. Security

Trip data is encrypted on your device before it leaves it, data in transit is protected with TLS, and server access is limited by security rules so that only members of a trip can reach its encrypted data. No system is perfectly secure, but we design Campfyr so that a breach of our servers would not expose your trip contents.

7. Children

Campfyr is not directed at children. If you are under 18, use Campfyr only with the involvement of a parent or guardian. If you believe a child has given us personal data without that consent, contact us and we will delete it.

8. Changes

If we change this policy we will update this page and its effective date, and tell you in the app when the changes are significant.