Overview
God's Plan stores data on your device and, when you sign in with Apple and iCloud is available, syncs the data described below through Apple's CloudKit. We do not operate a separate account database or sell your personal information.
Sign in with Apple
When you sign in with Apple, the app receives a pseudonymous user identifier and, only on your first authorization, the name and email you choose to share (including a Hide My Email address). The identifier is kept in the app's local Keychain and app storage to recognize your sign-in; it is not uploaded in your CloudKit profile. Your name and email are stored locally and synced as described below so your account details remain available across your devices. Your name is also used to prefill the public author byline on your Guide writer application, which you can change while applying. Once your application is approved that byline is fixed and appears on every post you publish.
iCloud Sync
While you are signed in with Apple, the app uses the public database of our CloudKit container to sync your non-sample travel plans, name, email, date and time display formats, award check-in history, and the searches you run in the mini apps — the routes, dates, cabin and the flight or hotel keywords you type, with the time, your language and the app version. Your imported hotel membership number, programme, points, status, night progress and pass expiry sync separately in your private CloudKit database inside an encrypted payload; other app users and the developer cannot browse that private database. Search records carry your account identifier, are governed by the Analytics Collection switch in Settings, and can be erased at any time in Settings under Behavior. CloudKit supplies an account-scoped identifier that addresses and owns synced records; the app keeps a local binding to that identifier to prevent an accidental upload after the device changes iCloud account. “Public database” describes the CloudKit database scope; for your plans and profile records, its security roles allow authenticated iCloud users to create records but allow only each record's creator to read or write them, so other app users cannot read those records. Guide posts are the deliberate exception: once approved they are public — readable by anyone using the app, including guests — and carry the byline you chose along with your post content and photos. A post you submit is stored in that same public database in a state the app does not display to other users until it is approved, and a post that is not approved stays stored, undisplayed, until you delete it or delete your account. Your writer application — the byline, biography, links and home region you submit, the email address from your Apple account so we can reach you about it, and the reason for any decision — is stored there too, readable only by you and the developer. You can delete any of your posts, and can edit and resubmit one that was not approved; the developer can approve, decline, or remove them. A post you report is recorded as a separate entry naming the post, your reason and any comment you add, readable only by you and the developer. The developer can access public records through Apple's CloudKit Dashboard or server APIs for support and administration. Guests do not sync data to CloudKit.
Third-Party Sign-Ins
If you sign in to an airline or travel service inside the app, your credentials go directly to that provider. Session data issued by the provider is stored on your device and can be cleared by signing out or deleting the app.
Wallet Pass Imports
When you choose or share an Apple Wallet pass, Apple's PassKit validates it on your device before the app reads its signed data. A pass shared from Wallet is held temporarily in an on-device App Group container shared only between God's Plan and its Share Extension so an interrupted import can resume; it is deleted after you finish or dismiss the import. Flight details you confirm become a travel plan and follow the iCloud sync rules above. Imported hotel membership numbers, programmes, points, status, night progress and pass expiry remain on this device for guests and sync in an encrypted payload through the signed-in user's private CloudKit database. They appear in a data export only when you choose to share one. The app does not otherwise keep the pass file, barcode, passenger or member name, web-service address or authentication token. A random key in your device Keychain creates a non-reversible local identifier so importing an updated copy refreshes the same item on that device; this identifier is not uploaded. Delete Account or Delete All Data removes that key and any pass waiting in the shared container.
Custom AI Provider
If you connect your own AI service in Chat settings, your chat messages, the app's tool results for your requests, and — only if you allow them — your saved plans and attached photos are sent to the server you configure. That server is chosen and operated by you or its vendor, not by us, and its handling of your data is subject to its own policies. The API key you enter is stored in your device Keychain and synced through iCloud Keychain; removing the provider deletes it. Apple Intelligence is not used while a custom provider answers.
Location
If you grant location access, your position shows where you are on maps, names the place you are in, and fetches current conditions there. Naming the place uses Apple's geocoding service and the conditions come from Apple's WeatherKit, and both receive your coordinates. Only the resulting place name, never your coordinates, is sent to a third-party photo service to fetch a background photo. If you have not answered the location prompt yet, or the device cannot get a fix, the app asks a third-party IP-geolocation service to estimate your city from your IP address; it does not do this if you declined location. We never store your position on our own servers.
Notifications
The app registers with Apple Push Notification service so CloudKit can deliver silent change notifications and, if you enable alerts, visible notifications. Apple issues a device-specific push token for delivery; the app does not persist, log, or copy that token into your CloudKit profile. You can disable visible notifications at any time in system settings.
Analytics and Diagnostics
The app uses Google's Firebase SDK for three things: Analytics records standard app-usage events such as screen views and session starts, Crashlytics reports crashes together with a stack trace, device model, system version and a short trail of navigation breadcrumbs, and Performance Monitoring times app start-up and network requests. The app logs no custom analytics events and sends Firebase no name, email address, travel plan, search term, or post content. Firebase assigns a random installation identifier so reports from one install can be grouped; it is not tied to your Apple account and is discarded when you delete the app. Google processes this data as our service provider under its own terms. Each of the three can be switched off in Settings, and all three are on until you switch them off. In TestFlight and other pre-release builds they are locked on so that beta problems are reported; your own choices resume on the App Store build.
Data Retention and Deletion
Signing out removes the active Apple sign-in credential from the app and stops syncing, but it does not delete your local data or CloudKit records. Deleting an individual plan immediately removes its itinerary details from CloudKit and retains only a minimal marker — record identifier, owner, and deletion time — until Delete Account, preventing an old offline device from restoring the deleted plan. Removing a hotel programme similarly syncs a marker without its membership details so another device cannot restore it. Delete Account removes your profile details and Plan records from CloudKit, deletes the private CloudKit zone containing your hotel loyalty snapshot, and then erases this app's local data, including its Keychain entries. Delete Account archives your Guide posts — published, awaiting review, and declined alike — so they are hidden from everyone; signing in again with the same iCloud account lets you restore them. Nothing returns to the feed on its own: a restored post goes back for review, and one that had already been declined stays declined. If you want posts permanently removed, delete them individually before deleting your account. Your writer application, your search records, and any abuse reports you filed are deleted with your account. A technical UserProfile tombstone containing only opaque generation and deletion markers and standard CloudKit metadata remains; it contains no profile details and prevents old devices from restoring deleted data. If cloud deletion fails, the app reports the error and retains the deletion state so the operation can be safely retried. Deleting the app alone may leave Keychain and CloudKit data behind, so use Delete Account first. Removing this app's Sign in with Apple authorization is a separate action in Apple Account settings.
Changes to This Policy
We may update this policy from time to time. Material changes will be reflected in the app.
Contact
Privacy questions can be sent to support@startway.io.