Privacy

What we collect, and why.

Short version: we store what you give us to build your trips, we don't sell it, and we don't track you around the web. Longer version below. This is a plain-language summary, not a substitute for legal advice, and it'll be reviewed by an actual lawyer before real payments go live.

What we collect

Account: your email, a hashed password (we never store the password itself), your handle, name, and anything optional you add - bio, home city, avatar.

Trips: whatever you log - titles, dates, locations, notes, costs, and photos. If a photo carries EXIF data (the date and GPS coordinates a camera or phone attaches automatically), that's read in your browser before the photo ever uploads, so you see exactly what was found before anything saves.

Nothing else. No cookies, no third-party ad trackers, no analytics pixels. Sign-in uses a token stored in your browser, not a cookie.

Who else sees it

A trip stays private until you make it public or publish it as a route. Photos are stored with our hosting provider (Netlify), not on a public bucket. Place names you enter may be looked up against Wikipedia's public API to find a representative photo - only the place name is sent, never anything about you.

If a photo-suggestion or text-import feature is active, a photo thumbnail or the text you pasted may be sent to Google's Gemini API to help draft a caption or parse an itinerary - always as a draft you review and edit before it saves, never published automatically.

Payments

Payment processing isn't live yet. When it is, card details will go directly to Stripe - we won't see or store them ourselves.

Deleting your data

You can delete any trip yourself, any time, from its edit page. Full self-service account deletion isn't built yet - a support channel for that request is coming before this page is considered final.