Plain English Summary
This policy covers the Āpex Suite apps from HYTimes Group LLC, currently Anticipāt, Trāce, Rōute, Pāck, and Spēnd, on iOS and Android, plus apps we add to the suite later. Here's what actually matters:
- We never make you create a HYTimes account, and we never sell or profile your data. There are no ads, no analytics, and no trackers in any of our apps.
- Your data lives on your device by default. Where an app syncs, it syncs through your own iCloud or Google account, not through anything we run.
- The one exception is live sharing: a packing list you share in Pāck, or a group you share in Spēnd, syncs through a Firebase project we operate so everyone's phones can see the same list. Only what you actively share goes there, and it's spelled out per app below.
- Some features reach the internet in the moment (maps, weather, exchange rates, photo search, confirmation parsing) and each one is described below. We don't store what comes back on any server of ours.
- Some apps include affiliate links that open in your browser. We may earn a commission, never at extra cost to you.
1. Who We Are & What This Covers
The Āpex Suite apps are developed and published by HYTimes Group LLC ("we," "us," "our"), a US-based company. This Privacy Policy applies to the Āpex Suite apps listed above, any additional Āpex Suite apps we release, the future unified Āpex Suite app, and their widgets, on both Apple iOS and Google Android. When a new app introduces a data practice not described here, we update this policy before that app relies on it.
If you have questions about this policy, contact us at privacy@hytimesgroup.com.
2. Our Core Principles
Three rules shape how every app in the suite handles data:
- On-device by default. Every app works fully offline. What you enter (trips, dates, packing lists, itineraries, places, expenses) is stored locally on your device. Online features are conveniences layered on top, and each is listed per app below.
- No new accounts. We never create or manage a HYTimes account for you, and there's no sign-up flow anywhere. Where sign-in exists (sharing in Pāck and Spēnd), it's the Apple or Google account you already have.
- We keep nothing we don't need. No user data lands on a HYTimes server except the lists and groups you actively share for live collaboration, and those are described plainly in Section 4. When an app uses an online service, it uses the result in the moment and keeps only the derived value on your device.
Your on-device data may be included in your device's own backup (Apple iCloud Backup or Android's backup service) if you have that enabled. Those backups are governed by Apple's and Google's privacy policies, not ours. We have no access to them.
3. What We Never Collect
Across the entire suite, we do not collect:
- Advertising identifiers (IDFA / GAID), device fingerprints, or cross-app tracking data
- Behavioral or usage analytics of how you use the apps
- Payment or card details. All purchases are handled entirely by Apple or Google.
- Your location. No Āpex Suite app requests location permission.
4. The Apps, One by One
Each app's data practices and the device permissions it may request:
Anticipāt · Countdown app · Free
Anticipāt ⏳
Countdowns, dates, destinations, notes, and any photo you attach are stored on your device. On iPhone and iPad, you can turn on sync, which stores your events in your own private iCloud database (Apple CloudKit). We can't read it. It's your iCloud, protected by your Apple ID. Nothing is stored on any server of ours. Optional permissions and online features:
- Notifications: to remind you before an event. Optional, asked in context.
- Photo Library: only the specific photo you pick as a countdown background; we never read your whole library.
- Calendar (read-only): if you use Calendar Import, events are read locally to suggest countdowns and discarded when you leave that screen. Never transmitted.
- Unsplash image search: if you search for a background image, the text you type (e.g. "Tokyo skyline") is sent to Unsplash to fetch photos. Only that search text is sent. See Unsplash's policy.
- Sharing a countdown creates an image on your device that you send through the system share sheet. Nothing is uploaded by the app.
Trāce · Travel map · Free
Trāce 🌍
The places you mark (visited, lived, booked, want to visit, transited) and your stats are stored on your device. On iPhone, your country and state statuses also back up through your own iCloud (the iCloud key-value store), so a new phone comes back filled in. That's your iCloud, not ours, and it does nothing at all if iCloud is off.
Trāce's interactive map is rendered by the Mapbox Maps SDK. To draw the map, Mapbox receives standard map-tile requests and, by default, collects de-identified usage and approximate-location telemetry from the map view. We do not receive or store this telemetry; it is handled by Mapbox under Mapbox's privacy policy. You can opt out of Mapbox telemetry directly on the map: tap the information (ⓘ) icon and choose the telemetry setting.
If Anticipāt is installed on the same phone, the two apps can exchange trip suggestions through a shared on-device container. Nothing leaves the phone, and every suggestion asks you first. Share images are generated on your device. Trāce has no accounts, no ads, and no third-party services other than Mapbox.
Rōute · Itinerary planner · $4.99 once
Rōute 🗺️
Trips, day-by-day itineraries, confirmation numbers, attached confirmation PDFs, and notes are stored on your device, and every saved trip opens fully offline. On iPhone and iPad, trips sync between your own devices through your own private iCloud database (Apple CloudKit), never through a server of ours. Rōute requests no location permission at all. There is no account and no sign-in anywhere in the app.
Rōute's online conveniences, and exactly what each one sends:
- Confirmation parsing. When you import a booking confirmation (shared email text, pasted text, an uploaded PDF, or a Fora link), that text is sent to a parsing service we operate (a Cloudflare Worker), which passes it to AI services from Anthropic and Google to extract the booking fields, then returns them to your phone. We do not store the text or the result; the Worker has no database and no logging. Only the one confirmation you choose to import ever leaves the device; Rōute never touches your inbox. Offline, an on-device parser takes over.
- Live flight status. The flight number and date are sent to a flight-status service to fetch gates, terminals, and times.
- Weather and travel times. The coordinates and dates of your itinerary days are sent to weather and routing services to show forecasts and realistic travel times between stops.
- Notifications: for day-of reminders and flight alerts. Optional. Scheduled on your device.
- Photo Library: only if you pick a trip cover photo.
Each of these degrades quietly when you're offline. Rōute currently contains no affiliate links.
Pāck · Packing lists · $4.99 once
Pāck 🧳
Lists, items, templates, photos, and progress live on your device. Packing on your own makes no network calls at all. The online features, one by one:
- Weather suggestions. Pāck sends your destination's name and coordinates to Open-Meteo, a weather service that needs no key and no account, and reads back the forecast. Nothing about you is sent.
- Cover photo search sends your search text to Unsplash.
- Personal sync (opt-in, off by default). Your own lists back up to your own cloud: your iCloud Drive on iPhone, or a visible "Pāck" folder in your own Google Drive on Android. On Android this uses Google's
drive.file scope, which limits Pāck to files it created itself, so it cannot see the rest of your Drive. You can view and delete these files yourself.
- Shared lists. When you actively share a list, that list (its items, the display name you chose, and who marked what) syncs through Google Firebase (Firestore and Firebase Auth) in a project we operate, so people on different phones (including mixed iPhone and Android groups) can pack the same list together. No photos are uploaded except the list cover, and nothing else about your device is sent. You can end this at any time in Settings ("Stop sharing"), which removes the list from live sync.
- Sign-in. Sharing signs you in silently with an anonymous session. You can optionally attach the Apple or Google account you already have so shared lists survive a new phone. We never create a HYTimes account.
Pāck's affiliate links (Amazon, Airalo, Faye) open in your browser; see Section 5.
Spēnd · Trip budgets & group splitting · $4.99 once
Spēnd 💰
Solo use needs no account and no network. Budgets, expenses, splitting, settling up, and CSV export all work on-device and offline, with no sign-in anywhere. That's the default, and nothing below applies until you share a group.
- Sharing a group uses an account you already have. Sharing or joining a live group requires signing in with Apple or Google (federated through Firebase Auth), so your groups survive a lost phone. Viewers who only look at a group can join anonymously. We never create a HYTimes account, and sign-in is only ever prompted when you share or join.
- What syncs, and only what syncs: participants, expenses and their splits, payments, funds, comments, and group details. These live in a Google Firebase (Firestore) project operated by HYTimes Group LLC while the group is shared.
- What never syncs: receipt photos never leave the device that took them. Balances are never transmitted; each device works out who owes whom from the synced rows itself.
- Push notifications. If you allow them, a device token is stored in the shared group so our notification function can reach you. It's removed when you leave the group or stop sharing. Notifications are only ever about activity in a group you joined, never marketing.
- Exchange rates. Spēnd fetches a daily currency rate table from a public feed. No user data is sent to get it, and the table is cached on your device.
- Receipt scanning is on-device. Apple Vision or ML Kit reads the receipt on your phone, and only the values you keep are stored. The image is never uploaded. Camera and Photo Library permissions are requested only for the receipt you're adding.
- Deleting your account. Settings has a delete-account control. It deletes the account and strips your user ID, name, and payout handles out of every shared group. Expenses you added stay, because they're part of other people's balances too. Details: hytimesgroup.com/spend/delete-account.
Where the shared copy lives, and for how long. Shared group documents sit in a Firebase project operated by HYTimes Group LLC, and they delete themselves on a schedule: 30 days after the owner ends the share, or 12 months after a group goes untouched. Everyone keeps their own copy on their own phone either way, because the shared copy exists for live collaboration, not for archiving. You can stop sharing or leave a group whenever you want, and if you want the shared copy gone sooner than the schedule, use the in-app controls or email us.
5. Affiliate Links & Disclosure
Some Āpex Suite apps (currently Anticipāt, Pāck, and Spēnd) include outbound links to third-party travel services such as gear retailers, eSIMs, travel insurance, and hotels. As required:
"HYTimes App Studio may earn a commission on purchases made through links in this app. This never affects our recommendations or your price."
Affiliate links open in your device's external browser (Safari or Chrome), not inside the app. Once you leave the app, the destination site and its affiliate network may set cookies and process data under their own privacy policies; that activity is outside our apps and outside our control. Trāce and Rōute contain no affiliate links; their only outbound links are to our own apps and to HYTimes Travel.
6. Third-Party Services
The complete list of third parties any Āpex Suite app may interact with:
- Apple App Store & Google Play: process all purchases. We receive confirmation that a purchase occurred but never your payment details.
- Apple iCloud / CloudKit (Anticipāt, Rōute, Trāce, and Pāck personal sync): syncs your own data into your own iCloud. Governed by Apple's privacy policy; we have no access.
- Google Drive (Pāck personal sync on Android): a "Pāck" folder in your own Drive, limited to files Pāck created.
- Google Firebase (Pāck and Spēnd, sharing only): Firestore and Firebase Auth power live shared lists and groups, in projects we operate. Firebase privacy.
- Mapbox (Trāce only): renders the map; receives map-tile requests and de-identified telemetry. Privacy policy.
- Unsplash (Anticipāt and Pāck): receives the image-search text you type. Privacy policy.
- Open-Meteo (Pāck): receives a destination name and coordinates for the forecast.
- Our parsing service, with Anthropic and Google AI (Rōute only): receives the one booking confirmation you choose to import, returns structured fields, stores nothing.
- Flight-status, weather, and routing services (Rōute): receive a flight number and date, or trip-day coordinates and dates, to show live status, forecasts, and travel times.
- A public exchange-rate feed (Spēnd): provides the daily currency table. No user data is sent.
- Affiliate partners (various apps): reached only when you tap an outbound link in your browser; governed by their own policies.
- HYTimes Travel: our own travel-advisory service, linked from some apps; opening it takes you to a webpage in your browser.
None of the Āpex Suite apps contain third-party advertising SDKs, analytics platforms (such as Firebase Analytics, Mixpanel, or Amplitude), or data-broker integrations. Where sign-in exists, it's Sign in with Apple or Google for the sharing features described above, never a HYTimes login.
7. Device Permissions & How to Revoke Them
Apps request permissions only when you use the feature that needs them, and the apps work without them. You can revoke any permission at any time:
- iOS: Settings → Privacy & Security → (Notifications / Photos / Camera / Calendars) → select the app.
- Android: Settings → Apps → (the app) → Permissions.
8. Children's Privacy
The Āpex Suite apps are not directed to children under 13 (or the equivalent minimum age in your jurisdiction) and we do not knowingly collect personal information from them. If you believe a child has shared personal information with us through a shared list or group, email us and we'll delete it.
9. Data Security
Your on-device data is protected by your device's built-in security (passcode, Face ID, Touch ID, fingerprint) and the operating system's app sandboxing. Data synced through your own iCloud or Google Drive is protected by Apple's and Google's security. The shared lists and groups described in Section 4 live in Google Firebase projects with per-user security rules, so only the people in a list or group can read it. We keep those projects to the minimum: no analytics, no copies, nothing beyond what live sharing needs.
10. Your Rights (GDPR, CCPA & Others)
Privacy laws such as the GDPR (EU/UK) and CCPA (California) give you rights to access, correct, and delete personal data a company holds about you. For everything stored on your device or in your own iCloud or Google Drive, you already have full control: it's yours, and deleting the app (or the files) removes it.
For shared lists (Pāck) and shared groups (Spēnd), which are the only user data we hold: you can stop sharing or leave at any time in the app, Spēnd offers in-app account deletion (Settings → Delete account, or see this page), and you can email privacy@hytimesgroup.com to have anything we hold about you retrieved or deleted. We do not sell or share personal information for advertising, in any app, ever.
11. Changes to This Policy
If we update this Privacy Policy, we will post the updated version here and update the "Last Updated" date above. For material changes, we will provide a more prominent notice in the affected app. Your continued use of an app after changes take effect constitutes acceptance of the updated policy.
12. Contact