Legal

Privacy Policy

Last updated: July 7, 2026

What we store

  • Account data: your email address and display name, managed by our authentication provider (Supabase Auth).
  • Trip data you enter or approve: trips, travelers, constraints, destinations, days, activities, flight and accommodation details, contacts, notes — plus a version history of every approved change and the cautions attached to them.
  • Connections: if you connect an AI assistant over MCP, we store the app’s registration, your consent (scopes), and hashed refresh tokens — never plaintext secrets. Share links are stored as hashes only.
  • Cached public data: sunrise/sunset times per coordinate and date — astronomical facts, not personal data.

What leaves our servers

Very little, and never for advertising. To look up places and sun times we send place-name queries and coordinates + dates to public data APIs (Open-Meteo geocoding, SunriseSunset.io) — server-side, without your identity attached. If you connect Claude (or another MCP client), your trip content and constraints are shared with that assistant, at your instruction, under the scopes you approved; revoking the connection in Settings stops it immediately. Share links expose exactly the read-only view you created, to whoever holds the link, until you revoke it.

What we don’t do

  • No selling or renting of personal data. No ad networks.
  • No inference about your religious practice beyond what you chose to write down — constraints are stored verbatim and used only as context you hand to your assistant.
  • No third-party analytics on trip content; operational logs are for reliability and security.

Sensitive data, handled deliberately

Observance-related constraints (e.g. “keeps Shabbat”, “kosher only”) can reveal religious affiliation. We treat all trip content as private by default: it is protected by row-level security so only trip members can read it, connected assistants act under your own permissions, and nothing is public unless you create a share link.

Your rights

Self-serve, in Settings: export your data as JSON at any time, and delete your account — which revokes all connected apps and share links, removes you from shared trips (ownership transfers to a co-traveler), and permanently deletes trips only you own. Depending on your jurisdiction you may have additional rights (access, rectification, erasure, portability, objection); exercising them starts with the same export/delete tools or the site’s contact details.

Storage, security, retention

Data is stored with managed providers (Supabase/PostgreSQL for data and auth; our hosting provider for the application), in transit over TLS and encrypted at rest by those providers. Access-control checks are enforced in the database itself and covered by automated tests. We keep trip data for as long as your account exists; deleting a trip or your account removes it, and backups expire on the provider’s schedule.

Cookies

We use only the session cookies required to keep you signed in. No tracking cookies.

Children

Accounts are for adults. Children appear in trips only as roster entries their guardians typed in (a name and age group); the “kids view” share link contains only trip content you chose to share.

Changes and contact

Material changes to this policy will be posted here with a new date. Questions: see the contact details published on this site, and our Terms of Service.