Updated 4 October 2026. Preview build; sign-in and Premium require configuration. Controller: Lê Hà Khôi Nguyên / SakuraGo. Contact: central_hub@auro-log.com.
Guest use Maps, routing and the library work without signing in. Place source names, IDs, coordinates, trip plans, accommodation, notes and selected photos are saved in the app container. Uninstalling can remove local data that was not exported or synced.
Location and external services With permission, location is used for places, directions, weather and destination dwell recognition. Always-on background location is not requested. Necessary queries, coordinates and your IP address are sent to Apple Maps; Photon/OpenStreetMap and Valhalla for fallback; Open-Meteo for weather; Wikipedia for guide references. Each service has its own privacy terms and coverage limitations.
Optional accounts and sync You can sign in with Apple, Google or Microsoft when configured. Providers supply an account identifier and may supply a name/email, including Apple relay email. Sign-in screens are managed by the provider; SakuraGo never receives passwords. SakuraGo sessions stay in Keychain; the server stores token hashes. Google/Microsoft request only openid, profile and email, with no access to mail, calendars or contacts and no retained provider access/refresh tokens. Enabling sync sends your trip library, saved places, journal and notes to Cloudflare Workers/D1. Journal data can reveal where and when you visited. Guest imports require your explicit choice. Accounts are separated by provider, issuer and subject, never automatically merged by email. Another provider can create a separate notebook.
Photos and voice Only photos selected in the iOS picker are imported. New smaller JPEG copies remove source metadata and currently remain on the device; photos are not synced. Speech uses local models/system voices. Voice recognition requests on-device recognition only when available. Microphone use starts only when you choose voice input and grant permission.
Subscriptions If offered, App Store handles Premium payments and StoreKit verifies entitlements. SakuraGo receives no payment card information. Actual prices and periods are shown before purchase. Ride or flight booking is not included.
Retention and choices Local data stays until deleted. Cloud data remains while the account is active; disabling sync does not delete previously synced data. Export data, delete individual items, or delete your account inside the app after fresh verification with your sign-in provider. Deletion removes live account data and sessions and revokes Apple/Google authorization. For Microsoft, SakuraGo deletes its own sessions and app data without signing you out of other Microsoft services. Recovery copies may remain during the applicable Cloudflare D1 Time Travel window, which must be confirmed before release. Deleted data must not be reused; deletion requests must be reapplied before restoring backups. Account deletion does not cancel Apple subscriptions or remove guest data, shared copies or exported files.
Tracking This build has no advertising or cross-app tracking SDK and does not sell data. Short-lived hashed IP buckets limit abuse. App logs do not contain tokens or GPS; infrastructure may retain operational logs under provider policies.
For access, correction or deletion help: central_hub@auro-log.com. Policies and provider details must be checked against the release build before App Store submission.