Privacy Policy
Clear information about your travel workspace and how to control it.
Preview policy template · Updated 6 October 2026. The operator must complete actual provider, jurisdiction, contact and backup details before a public launch.
Information we collect
For an account, we process your email and authentication information through Supabase Auth. For travel planning, we keep the conversations and preferences you choose to provide: origin country, travel dates, travelers, budget, cities, interests and relevant dietary or accessibility needs. A custom consultation may also collect email and optional WhatsApp details. We do not need passport photos, visa images, card numbers or full payment-card details for this first-stage planning service.
Why we use this information
We use it to answer travel questions, keep your trip workspace, personalize routes and handle a consultation you request. Long-term travel preferences remain separate from each trip's specific profile. Account and guest-session checks restrict access to the corresponding user's records. Administrator access is separate and requires authorization.
AI processing and public knowledge
Public travel documents form the knowledge base. Private conversations, names, contact details, consultations and itineraries are not automatically indexed into public RAG. When an external AI provider is enabled, the server minimizes travel context and removes common contact identifiers and sensitive tokens before making the request. Automated redaction is a best-effort safeguard; do not enter unnecessary identity or payment details in a travel conversation. The active provider and its data terms must be disclosed before production use.
Cookies and browser storage
Essential cookies support account authentication, signed guest sessions and security checks. Browser storage may hold local favorites, draft preferences or unfinished plans. This starter version does not install advertising pixels or marketing analytics. If optional analytics or marketing tracking is added later, the policy and consent controls must be updated before it is enabled.
Services and security
The configured deployment may use Supabase for authentication and data, a hosting provider, an optional server-side AI provider and a configured payment link for consultation fees. Only data required by those functions should be sent. Provider secrets remain in server environment variables. Production hosting, processing regions, provider names and backup arrangements must be completed in this template before launch.
Retention
Anonymous planning data is temporary, with a configured maximum of 14 days. The current consultation retention setting is 365 days and audit-log retention is 90 days. Account workspace data remains available while the account is active unless you remove it or a configured policy applies. Necessary paid accounting records may be anonymized and retained only when that option is enabled. Backups and production deletion deadlines must match the operator's final policy.
Your controls and deletion
In Privacy & Data you can inspect your profile, conversations and trips; export the workspace as JSON; delete individual trips or conversations; clear chat history; request deletion of personal data; and delete a signed-in account. Destructive actions require a confirmation phrase and remove server-side records. Deleting an account clears linked private planning data; any configured accounting retention is shown before deletion. Clearing browser storage alone does not delete server records.
Contact
The privacy contact address is not yet configured for this preview. Before public launch, the operator must provide a working contact address. The in-site Privacy & Data controls are available in your workspace.