runtrip
Legal

Privacy Policy

This policy explains what we collect when you plan trips with Runtrip, why we collect it, and the control you have over it. We wrote it to be read — no dark patterns, no buried clauses.

Last updated August 8, 2026

1. Who we are

Runtrip is an AI travel-planning service. The data controller responsible for the personal data described in this policy is Runtrip.ai. You can reach us about anything in this policy at care@runtrip.ai.

2. What we collect

You can start planning without creating an account. When you first use the planner we issue your browser an anonymous session identifier, and everything below hangs off that until (and unless) you sign in.

  • Session identifier — a random, unguessable token stored in an essential cookie, so your trips are still there when you come back. It is not linked to your name unless you sign in.
  • Trip inputs — the destinations, dates, traveller counts, budgets, and preferences you type into the planner, as free text.
  • Generated plans — the itineraries we build for you, their revision history, and any edits you make, so you can return to and undo them.
  • Conversation history — the messages exchanged with the planner, which give it the context to refine a plan.
  • Account details — if you sign in or subscribe, your email address and subscription status. We never see or store your password: sign-in and payment are handled by our payments provider (see §7).
  • Technical data — your IP address, recorded briefly to rate-limit abuse, and error diagnostics if something breaks.

Two further categories are collected only if you switch analytics on in the cookie banner, and not otherwise:

  • Product analytics — which pages you opened, which features you used, and where a plan generation succeeded or failed, as named events with structured values. They are tied to the same session identifier as your trips. They never carry your trip brief, your destinations as free text, or your email address.
  • Session replay — a recording of your own interaction with the page: what you clicked, how far you scrolled, how the layout responded. This is a new category of data about you rather than about your trip, so we are specific about the limits: what you type is masked, and so is the plan we generate for you, meaning the recording shows the shape of the page and your movement through it but not the content of your brief or your itinerary. Our payment provider's checkout screens are never recorded.

3. How we use it, and on what basis

We use your data to run the service and for nothing else. We do not sell your personal data, and we do not use the content of your trips for advertising. Under the GDPR, each purpose rests on a legal basis:

  • To generate and refine your itineraries, and to keep them available across visits — performance of our contract with you.
  • To operate accounts, subscriptions, and paid-feature limits — performance of our contract with you.
  • To rate-limit requests, prevent abuse, and diagnose errors — our legitimate interest in keeping the service available and secure.
  • To produce anonymised, aggregated statistics for our public destination guides — our legitimate interest in improving and promoting the service (see §5).
  • To understand how the product is used, through product analytics and session replay, and — if we ever start it — for email marketing or matching a subscription back to the ad that brought you here: your consent, and nothing else. Not legitimate interest. You give it in the cookie banner, you can withdraw it at any time on /cookies, and withdrawing costs you no functionality.

4. AI processing

Runtrip is built on large language models. To generate a plan, the text you write in the planner — together with the trip context needed to answer it — is sent to our AI provider through the Vercel AI Gateway and processed on their servers, which are located outside the EEA (see §8). Please do not enter sensitive personal information, payment card details, or anything you would not want processed by a third-party AI provider.

We do not use your conversations to train our own models. We rely on our AI providers' standard data-processing terms for how long they may retain a prompt on their side; check the provider's current policy for specifics.

We also measure what each AI call costs us — which model ran, how long it took, how many tokens it consumed, and the resulting price — and send that measurement to PostHog (§7). The prompt and the model's answer are explicitly excluded: PostHog is configured so neither is transmitted, so your brief and your itinerary never reach it. This measurement is about our own infrastructure cost, so it runs whatever you choose in the cookie banner; it is linked to you only if you have consented to analytics.

5. Destination guides & anonymised aggregates

We publish public city guides that are enriched with anonymised, aggregated planning data drawn from trips created on Runtrip — for example how many trips were planned to a city, the typical trip length, the popular months, and a typical flight-price range. These are statistics about a destination, never about a person: they contain no free text, no identifiers, and nothing that could single you out.

Two safeguards keep it that way. Aggregate statistics are only published for a destination once it passes a minimum threshold of distinct trips, so a small number of travellers can never be reverse-engineered from the numbers. And an individual itinerary is only ever displayed or linked publicly if you explicitly chose to share it via a share link — trips you keep private are counted in the anonymous totals but never surfaced.

If you would rather your planning not feed these statistics, email care@runtrip.ai and we will delete the trips in question — once deleted they are no longer counted in any future refresh. Statistics already published are anonymous and aggregated, so they contain nothing that can be traced back to you.

6. Sharing a trip

Your trips are private by default. If you create a share link for a trip, anyone with that link can view that itinerary — it is unlisted rather than secret, so treat the link as public. You can revoke a share link at any time, which immediately stops it resolving. A revoked trip is also withdrawn from the sample itineraries shown in the destination guides, though — like any private trip — it stays part of the anonymous totals described in §5.

7. Third parties we rely on

We keep the list short and share the minimum each one needs. These providers process data on our instructions under data-processing agreements:

  • Vercel — hosting, plus privacy-friendly analytics and performance metrics that set no cookies and do not track you across sites.
  • Supabase — the database where your trips, messages, and account records are stored.
  • Vercel AI Gateway and the AI model providers behind it — to generate and refine plans (see §4).
  • Travelpayouts — to fetch live flight and hotel availability and prices. We pass search parameters such as routes, dates, and traveller counts; we do not pass your identity. Booking links carry an affiliate marker, so we may earn a commission if you book.
  • Open-Meteo — to fetch the weather forecast for your destination and dates.
  • Unsplash — destination photography. Most images are fetched by our servers and re-served from Runtrip, but some are embedded straight from Unsplash's image CDN: for those, your browser requests the file directly and Unsplash sees your IP address and browser type. We send them nothing else about you, and no trip content.
  • Sentry — error monitoring, so we can diagnose crashes.
  • PostHog — product analytics and session replay, only if you consent (see §3 and the Cookie Policy). It receives the named events and replays described in §2, your session identifier, the page addresses you visited with any campaign parameters they carried, and the AI cost measurements in §4. It does not receive your email address, your trip brief, or the text of a generated plan. Its EU Cloud is hosted in Germany, so this data stays in the EEA.
  • monetize.software — sign-in, subscriptions, and payment. They handle your credentials and card details directly; we only receive your email address and whether your subscription is active. We never see your card number or password.

8. International transfers

Some of the providers above process data outside the European Economic Area, principally in the United States. Where that happens we rely on the European Commission's Standard Contractual Clauses, or the provider's certification under an applicable adequacy framework, to protect your data. You can ask us for details of the safeguards that apply to a specific provider.

9. Data retention

We keep your trips and conversation history for as long as your account is active, so you can come back to them. Anonymous sessions and their trips are retained for up to 12 months of inactivity and then deleted. Rate-limiting records containing IP addresses are short-lived and rotate out automatically. If you ask us to delete your data, we remove it from active systems within 30 days; residual copies in encrypted backups are overwritten on our provider's backup cycle, currently 7 days.

Anonymised aggregate statistics (§5) are not personal data and may be retained after deletion, since they can no longer be linked to you.

10. Your rights

If you are in the EEA or the UK, you have the right to access the personal data we hold about you, to correct it, to delete it, to restrict or object to how we use it (including the aggregate statistics in §5), and to receive it in a portable format.

To exercise any of these, email care@runtrip.ai from the address on your account, or — if you plan anonymously — from any address, telling us the share link or trip you mean so we can locate the right session. We respond within 30 days, free of charge. You can also export an itinerary yourself as a PDF from that trip's share menu, without contacting us.

If you think we have handled your data badly, please tell us first — but you also have the right to complain to your national data-protection authority.

11. Contact

Questions about your privacy, or want your data exported or deleted? Reach us any time — we aim to reply within two business days, and always within 30.

Email care@runtrip.ai →
runtrip
The AI travel planner that talks like a friend, books like a pro, and saves you a Saturday.
Product
Destinations
Company
© 2026 Runtrip. Made for travellers, not booking funnels.