Privacy Policy
This policy explains what we collect when you plan trips with Runtrip, why we collect it, and the control you have over it. We wrote it to be read — no dark patterns, no buried clauses.
1. Who we are
Runtrip is an AI travel-planning service. The data controller responsible for the personal data described in this policy is [TO CONFIRM: legal entity name], [TO CONFIRM: registered address]. You can reach us about anything in this policy at privacy@runtrip.app.
2. What we collect
You can start planning without creating an account. When you first use the planner we issue your browser an anonymous session identifier, and everything below hangs off that until (and unless) you sign in.
- →Session identifier — a random, unguessable token stored in an essential cookie, so your trips are still there when you come back. It is not linked to your name unless you sign in.
- →Trip inputs — the destinations, dates, traveller counts, budgets, and preferences you type into the planner, as free text.
- →Generated plans — the itineraries we build for you, their revision history, and any edits you make, so you can return to and undo them.
- →Conversation history — the messages exchanged with the planner, which give it the context to refine a plan.
- →Account details — if you sign in or subscribe, your email address and subscription status. We never see or store your password: sign-in and payment are handled by our payments provider (see §7).
- →Technical data — your IP address, recorded briefly to rate-limit abuse, and error diagnostics if something breaks.
3. How we use it, and on what basis
We use your data to run the service and for nothing else. We do not sell your personal data, and we do not use the content of your trips for advertising. Under the GDPR, each purpose rests on a legal basis:
- →To generate and refine your itineraries, and to keep them available across visits — performance of our contract with you.
- →To operate accounts, subscriptions, and paid-feature limits — performance of our contract with you.
- →To rate-limit requests, prevent abuse, and diagnose errors — our legitimate interest in keeping the service available and secure.
- →To produce anonymised, aggregated statistics for our public destination guides — our legitimate interest in improving and promoting the service (see §5).
4. AI processing
Runtrip is built on large language models. To generate a plan, the text you write in the planner — together with the trip context needed to answer it — is sent to our AI provider through the Vercel AI Gateway and processed on their servers, which are located outside the EEA (see §8). Please do not enter sensitive personal information, payment card details, or anything you would not want processed by a third-party AI provider.
We do not use your conversations to train our own models. [TO CONFIRM: whether zero-data-retention is actually in force for the gateway/provider configuration in use, and whether the provider is contractually barred from training on prompts. If confirmed, state it plainly here — it is a strong and reassuring claim, but it must be true.]
5. Destination guides & anonymised aggregates
We publish public city guides that are enriched with anonymised, aggregated planning data drawn from trips created on Runtrip — for example how many trips were planned to a city, the typical trip length, the popular months, and a typical flight-price range. These are statistics about a destination, never about a person: they contain no free text, no identifiers, and nothing that could single you out.
Two safeguards keep it that way. Aggregate statistics are only published for a destination once it passes a minimum threshold of distinct trips, so a small number of travellers can never be reverse-engineered from the numbers. And an individual itinerary is only ever displayed or linked publicly if you explicitly chose to share it via a share link — trips you keep private are counted in the anonymous totals but never surfaced.
If you would rather your planning not feed these statistics, email privacy@runtrip.app and we will delete the trips in question — once deleted they are no longer counted in any future refresh. Statistics already published are anonymous and aggregated, so they contain nothing that can be traced back to you.
7. Third parties we rely on
We keep the list short and share the minimum each one needs. These providers process data on our instructions under data-processing agreements:
- →Vercel — hosting, plus privacy-friendly analytics and performance metrics that set no cookies and do not track you across sites.
- →Supabase — the database where your trips, messages, and account records are stored.
- →Vercel AI Gateway and the AI model providers behind it — to generate and refine plans (see §4).
- →Travelpayouts — to fetch live flight and hotel availability and prices. We pass search parameters such as routes, dates, and traveller counts; we do not pass your identity. Booking links carry an affiliate marker, so we may earn a commission if you book.
- →Open-Meteo — to fetch the weather forecast for your destination and dates.
- →Unsplash — destination photography. Most images are fetched by our servers and re-served from Runtrip, but some are embedded straight from Unsplash's image CDN: for those, your browser requests the file directly and Unsplash sees your IP address and browser type. We send them nothing else about you, and no trip content.
- →Sentry — error monitoring, so we can diagnose crashes.
- →monetize.software — sign-in, subscriptions, and payment. They handle your credentials and card details directly; we only receive your email address and whether your subscription is active. We never see your card number or password.
8. International transfers
Some of the providers above process data outside the European Economic Area, principally in the United States. Where that happens we rely on the European Commission's Standard Contractual Clauses, or the provider's certification under an applicable adequacy framework, to protect your data. You can ask us for details of the safeguards that apply to a specific provider.
9. Data retention
We keep your trips and conversation history for as long as your account is active, so you can come back to them. Anonymous sessions and their trips are retained for up to [TO CONFIRM: retention period, e.g. 12 months] of inactivity and then deleted. Rate-limiting records containing IP addresses are short-lived and rotate out automatically. If you ask us to delete your data, we remove it from active systems within 30 days; residual copies in encrypted backups are overwritten on our provider's backup cycle, currently [TO CONFIRM: backup retention window from the Supabase plan].
Anonymised aggregate statistics (§5) are not personal data and may be retained after deletion, since they can no longer be linked to you.
10. Your rights
If you are in the EEA or the UK, you have the right to access the personal data we hold about you, to correct it, to delete it, to restrict or object to how we use it (including the aggregate statistics in §5), and to receive it in a portable format.
To exercise any of these, email privacy@runtrip.app from the address on your account, or — if you plan anonymously — from any address, telling us the share link or trip you mean so we can locate the right session. We respond within 30 days, free of charge. You can also export an itinerary yourself as a PDF from that trip's share menu, without contacting us.
If you think we have handled your data badly, please tell us first — but you also have the right to complain to your national data-protection authority.
11. Contact
Questions about your privacy, or want your data exported or deleted? Reach us any time — we aim to reply within two business days, and always within 30.
Email privacy@runtrip.app →