1. Information Otinerary handles
Account and profile information
Otinerary uses your email address, authentication account identifier, display name, account status, and security credentials managed through Supabase Auth. You may separately claim an immutable public username, choose whether that public profile is visible, and explicitly connect publications to it.
Private Trip information
A private Trip can include its title, destinations, actual travel dates, invite code, members and roles, day assignments, selected Place identifiers and location snapshots, visit times, durations, notes, status and reservation-related state, tags, and collaboration history.
Public discovery and adoption information
Otinerary stores separate sanitized public itinerary snapshots when an owner publishes, private Saved bookmarks, and records needed to count unique successful Copies. Saver and copier identities are not public.
Session and security information
Supabase Auth session cookies keep you signed in and rotate the session safely. The browser also stores limited attempt state for selected authentication rate limits. Server-side request IDs and bounded security events may be processed to protect the service without placing credentials or private request bodies in application error logs.
2. How information is used
Information is used to authenticate accounts, provide private collaboration, enforce member permissions, create and display explicitly published snapshots, power Explore, maintain private Saved items and independent Copies, provide account recovery, process account deletion, and protect Otinerary from misuse.
3. Private Trips and public itineraries are separate
A private Trip is never made public directly. Publishing is an explicit owner action that creates or rebuilds a separate public snapshot from an approved set of Place-only itinerary fields.
Kept private
- Actual travel dates
- Members and email addresses
- Invite codes
- Private notes and reservations
- Collaboration history
- Private Trip IDs and source mappings
- Saver and copier identities
May be public after Publish
- Public title and day count
- Day and Place ordering
- Publishable Place identity
- Trip-style tags
- Optional, explicitly attached public username
- Unique-user Copy count
Unpublishing removes public readability. Republish rebuilds the snapshot after the private source has been edited.
4. Maps and Place data
Search and standard route estimates · Geoapify
Destination and Place search text and language settings are sent to Geoapify through Otinerary servers. Selected Places retain provider identifiers, names, addresses, coordinates, and attribution for trip planning. Walk, Drive, Bike, and Rideshare estimates send stored origin and destination coordinates and the selected mode to Geoapify. Estimates run only on request and are not stored by Otinerary as route-result history.
Maps and Transit routes · Google Maps Platform
Itinerary maps use the Google Maps JavaScript API. When the Transit feature is enabled and you select Transit, stored origin and destination coordinates are sent from Otinerary's server to the Google Routes API. Time, distance, geometry, stops, lines, and agency information from one response are shown only in the current view and are not stored. The Trip date is not sent; the request-time departure basis is used, and the result is not real-time service status. Google may process map or route requests and connection information such as your IP address. Google Places API is not used.
Google map logos and terms attribution, and Geoapify and OpenStreetMap data attribution, remain visible in context. Each provider handles information under the policies below. Opening external directions uses the policies of the Google Maps or Apple Maps service you choose.
5. Service providers used by the current product
- Supabase provides authentication, session handling, and the Postgres data service.
- Vercel hosts and delivers the Otinerary web application.
- Geoapify provides destination and Place search and user-requested route estimates.
- Google Maps Platform displays interactive itinerary maps.
- Resend is the configured email delivery provider for Supabase account-recovery messages.
Otinerary's current production dependencies do not include a separate advertising or product-analytics SDK. This policy will be updated if the product's processing or service-provider set materially changes.
6. Retention, unpublishing, and account deletion
Otinerary does not state a fixed general retention period in this version. Product data remains associated with the relevant account, Trip, publication, Saved item, or Copy relationship until an in-product lifecycle action changes or removes it.
Self-service account deletion requires current-password verification, an exact confirmation phrase, and acknowledgment. It deletes Trips and publications you own; removes memberships, Saved rows, adoption identity, public identity, and matching private tombstones; and anonymizes your attribution on content retained in another owner's Trip. An independent Trip that another person previously copied remains theirs. The verified Auth user is deleted only after application-data cleanup succeeds.
7. Your choices
- Keep a Trip private and choose whether to Publish or Unpublish it.
- Keep a public profile hidden or explicitly attach it to a publication.
- Remove private Saved bookmarks.
- Change your password or delete your account from Profile while signed in.
- Use the Contact page for the current privacy-request and account-access path.
8. Policy updates and contact
The date at the top of this page identifies the current version. Material changes to Otinerary's documented practices will be reflected in an updated policy.
For privacy or data questions, visit Contact and account help. That page shows the contact options currently available.
