The Problem
Travellers in India juggle a maps app, a weather app, a translator, a review site and a notes app — and still have nothing useful when something actually goes wrong. Safety information is scattered, and emergency details live on paper.
Case Study · Android App · Flutter
Smart Travel & Safety Assistant
A native Android app that pairs a premium travel experience with real safety tooling — live Google Maps, an NVIDIA-powered AI guide, geofenced safety zones with Android notifications, a one-tap SOS flow, AI incident triage, a QR-verified Digital Emergency ID and an Eco Score. No demo buttons, no fake data, no "coming soon" screens — every feature is wired end-to-end.
01
Travellers in India juggle a maps app, a weather app, a translator, a review site and a notes app — and still have nothing useful when something actually goes wrong. Safety information is scattered, and emergency details live on paper.
One Flutter app with fourteen real feature areas, a Firebase backend and three AI pipelines. Every card on the dashboard navigates to a working screen; every network call hits a live API with proper loading, empty and error states.
No third-party secret ever ships to a device. NVIDIA, OpenWeather and the Google server key live only in Cloud Functions, and Firestore rules enforce every permission server-side — not just in the UI.
Everything is real and wired end-to-end. There are no demo buttons, no mock data and no placeholder screens. When the network fails the app says so and offers a retry — it never invents a result, and the SOS flow never claims that authorities were contacted when they were not.
02
Tap any screen to open it full size · 7 of the app's 14 feature areas
03
Flutter 3.32 on Dart 3.8 with Material 3, GoRouter for navigation and a lightweight service container instead of a DI framework. Native Android project targeting Android 7.0 and up.
Cloud Functions v2 on Node 20 act as the only API gateway. Authentication uses Google sign-in; Firestore and Storage hold app data behind security rules that are enforced server-side, including the admin role.
NVIDIA's Llama 3.1 70B instruct drives chat, itinerary JSON and incident triage. Google Places, Directions and Geocoding plus OpenWeather are proxied through the backend so their keys never reach the device.
Package
app.roamio.tourism
Primary Language
Dart · Node for functions
CI / CD
GitHub Actions · analyze + test + APK
Secrets In App
None · all server-side
04
Live location label, real weather, safety-zone status for your exact position, nearby attractions, latest alerts and one-tap access to SOS, Emergency ID and incident reporting. Every card navigates to a working feature.
Official Google Maps SDK with a live GPS dot, search markers, attractions, colour-coded safety circles and emergency services. Routes use a real Directions API polyline, with an honestly-labelled straight-line fallback when none is available.
Real Google Places text search plus category browsing for attractions, food and hidden gems — with proxied photos, ratings, price level, open/closed state, distance from you and hand-off to Google Maps navigation.
Conversational AI over NVIDIA Llama 3.1 70B with your current location and travel preferences injected as context. Typing indicator, suggestion chips and explicit error states when the model is unreachable.
Destination, days, interests, budget and travel style become a real AI-generated plan returned as structured JSON. Preview, regenerate, save to Firestore, browse day by day, or delete.
Nearest active zone, full zone list and a live geofence monitor. Entering a
high-risk zone fires an in-app warning plus a real
Android notification, and nearby emergency services are callable
with tel: links.
Confirm dialog → real GPS fix → an emergencyEvents record → an active-status screen with coordinates and accuracy, plus callable services nearby. It never claims the authorities were contacted.
Description, photo, video and location upload to Firebase Storage with type and size validation, then NVIDIA triage returns a category, severity, summary and recommended action that is stored for history and admin review.
A profile record whose QR code carries only a random 64-character
token — never personal data. Active/revoked states, copy-token, and a
real verification screen that scans with mobile_scanner and checks Firestore live.
GPS-tracked walking and cycling sessions accumulate real distance, or log an activity manually. Points, levels and badges persist in Firestore, with sessions under 50 m rejected rather than silently inflating your score.
Current conditions and a 5-day OpenWeather forecast with practical safety notes and full loading/error/retry states, plus a per-user notification history across safety, geofence, incident, emergency and weather events.
Name, photo, language, emergency contact and travel preferences in Firestore. The admin area — incidents, safety zones and SOS events — is role-gated in the app and enforced by security rules, so tampering with the UI changes nothing.
05
The Flutter app splits into core (theme, router, services, widgets), data (models and repositories) and features (one folder per screen group), so a feature can be read top-to-bottom without hunting across the tree.
The APK ships with zero third-party keys. Cloud Functions hold them as Firebase secrets and act as the single gateway, with per-user rate limits that clients are denied from reading.
GitHub Actions runs analyze & test (flutter analyze --fatal-warnings
plus flutter test) before a release build on JDK 17, then publishes
split APKs with checksums.
Firestore model. Incidents, safety zones and emergency events are
top-level collections; itineraries, notifications and eco activities are nested under
users/{uid}; digital IDs are keyed by a verification token. Admin access
is a role field on the user document that the rules check on every write —
never a flag the client can set.
06
Installing. Uninstall any older Tourism build first, download over
Wi-Fi, then tap the file and allow Install unknown apps. A "problem parsing
the package" message almost always means a truncated download — re-download and check
the size against SHA256SUMS.txt.
Building it yourself. flutter pub get then
flutter build apk --release, or trigger the Build APK workflow
on GitHub. The app needs your own Firebase project plus the NVIDIA, OpenWeather and
Google Maps keys set as function secrets — the repo README walks through it.