Draft — not yet reviewed
Privacy
Travel Planner is a shared notebook for a friend group planning one trip. This page says what we store, who can see it, and how to get rid of it.
What we store
When you sign in with Apple or Google, we store the name and email address that sign-in gives us. Beyond that, we store what your group puts into a trip: the trip itself, its plan items, places, ideas, expenses, and any files someone attaches — tickets, QR codes, confirmations.
Who can see it
A trip is visible only to the people in it — whoever holds the trip’s invite link and the people the organizer has added. Nobody outside your trip can see your itinerary, your expenses, or your files. There is no public feed and no directory of trips.
Who else touches your data
We use a small number of services to run the app, and nothing else:
- Railway — hosts our servers and database.
- Cloudflare R2 — stores the files you attach to a trip (tickets, QR codes, confirmations).
- Apple and Google — you sign in through them; we receive only the name and email they choose to share.
- Sentry — receives a report when the app or our servers crash or hit an error: what failed and where in the code, the app version, and your device model and OS. Each report is scrubbed before it is sent: no request contents, email addresses, sign-in tokens or IP addresses.
Destination names (the “Where?” field) are looked up against a public place dataset (GeoNames) that we host ourselves — nothing you type there is sent to a third party to answer it.
What we don’t do
No ads. We don’t sell your data, and we don’t share it with anyone outside your trip. We don’t run analytics or tracking on you or your trip.
Deleting your account and your data
We don’t yet have an in-app way to delete your account. Until we do, email us at [contact email] and we’ll delete your account and the trips you organize.
Who runs this
Travel Planner is operated by [operator name / country].