Last updated: August 12, 2026

Privacy Policy

MyTravelBuddy is an AI travel companion. This policy explains what we collect when you use the web app, related mobile clients, MCP connectors, and the marketing site that links here, and the choices you have.

1. Who we are

MyTravelBuddy (“we”, “us”) operates the product at https://app.mytravelbuddy.ai, the MCP resource at https://mcp.mytravelbuddy.ai, and related clients that talk to the same service. The marketing site at mytravelbuddy.ai links to this policy. By creating an account, using guest chat, or otherwise using the service, you agree to this policy and our Terms of Use.

2. Information we collect

Account and profile

Depending on how you sign in, we may store:

  • Name, email address, email verification status, and optional additional emails
  • Sign-in method (email one-time code, Google, or Facebook) and related authentication records
  • Optional profile details you provide: photo, phone number, birth date, gender, interests, food preferences, allergies, limitations, and a short description
  • Preferences such as theme, maps app, nearby search radius, and chat display style

Guest use

Guest mode uses an HTTP-only browser cookie to recognize the device. We do not create a guest database user, chat thread, or stored message until you agree to this policy and the Terms of Use on your first persisted message. Guest chat may be limited and later converted into a signed-in account.

Trip content you create

We store the trip workspaces you create or join, including:

  • Trip names, slugs, descriptions, cover images, dates, and planning-wizard answers
  • Dream ideas, wishlist items, and Questioner questions and answers shared with trip members
  • Itineraries, maps, checklists, packing lists, budgets, expenses, gifts, comments, and journal entries
  • Documents, photos, meal photos, and expense receipts you upload, plus generated thumbnails and extracted metadata (for example EXIF timestamps and GPS when present)
  • People records you add in My Circle and on a trip roster (names, relationship, birth dates used to derive age, notes, photos, and optional traveler identifiers such as a passport number)
  • Favorite places saved to your account, which can be associated with trips you can access

Chat, voice, and Buddy

  • Chat threads and messages, including files you attach
  • Voice conversations on an existing thread: we do not keep raw microphone audio on our servers. The browser talks to the voice provider over WebRTC. We store transcripts and session lifecycle records.
  • Buddy display name, avatar, personality instructions, and chat-style preferences you set. Long-term Buddy memories are stored only if you turn memory on.

Location

Location is off until you opt in. There are two separate controls:

  • Location awareness (for Buddy): we keep only your latest fix in a short-lived cache so Buddy can understand where you are. It expires after about 30 minutes, is not a history, and refreshes only while the app is open.
  • Share location with trip members: we save periodic samples on trips you open so members and invited observers can see you on Travel → Tracker. Photos, meals, and new journal entries can also carry the coordinates you had at that moment. Tracker can send enter/leave emails for places you subscribe to.

Uploaded photos and meal images may include GPS from the file itself even when sharing is off. You can strip location from a file before you upload it if you do not want that metadata stored.

Payments

If billing is enabled, Stripe collects card details on Stripe-hosted pages. We store Stripe customer, subscription, and transaction identifiers and status mirrors. We do not receive or store full card numbers.

Connected apps and MCP

If you connect an external client (for example ChatGPT, Claude, Grok, Perplexity, or a Connect with MyTravelBuddy app), we store the OAuth client, consent grant, and hashed tokens, plus which trip scopes you approved. Those clients then receive the trip information those scopes allow.

Device, usage, and diagnostics

  • Session IP address and user agent
  • Cookies and on-device storage described in section 7
  • Product analytics (PostHog when configured; Vercel Analytics and Speed Insights)
  • Error monitoring (Sentry when configured). A replay of the session around a crash may be captured, which can include on-screen content.
  • Internal admin event logs used to operate and debug the service

3. How we use information

We use this information to:

  • Authenticate you, keep you signed in, and enforce guest limits
  • Provide trip planning, collaboration, maps, weather, booking handoffs, and related features
  • Run Buddy (text and voice): compose prompts with your profile, trip context, consented memories, and relevant files, then generate replies and take the tool actions you request
  • Process images you upload when a feature needs it (meal dish descriptions, receipt totals, trip-story generation from metadata)
  • Send transactional email: sign-in codes, email verification, trip invitations, and tracker alerts
  • Process subscriptions and restore purchases through Stripe
  • Secure the service, prevent abuse, debug failures, and understand product usage
  • Comply with law and enforce our Terms of Use

4. AI and Buddy

Buddy is a shared assistant with a personal overlay (name, avatar, personality, preferences, and optional memory). Prompts sent to our AI providers typically include the current trip, your profile, chat history (with older images reduced to text stubs), and memories only when you have consented. Voice uses the same Buddy definition with shorter spoken replies.

Meal photos and expense receipts may be sent to a vision model to suggest titles, merchants, amounts, or categories. Chat tools that work with documents, photos, or meals return metadata, not file bytes or permanent public URLs.

Do not put secrets you are unwilling to send to subprocessors into chat, documents, or traveler fields. Model providers process prompts to generate responses and may retain data under their own policies.

5. Trip collaboration and visibility

A trip you create is visible to people you add as travelers, admins, or observers, according to their permissions. Default visibility:

  • Itinerary, Dream, journals (new entries), photos, and trip documents are trip-wide unless you mark an item private or share it with selected members
  • Meals are owner-only until you share them with claimed participants
  • Chat threads belong to the signed-in user on that trip; they are not a group inbox
  • My Circle contacts are your directory; trip travelers drawn from it become trip data

Public calendar feed URLs use a secret token. Anyone with the link can read the published itinerary until you rotate the token.

6. Cookies and on-device storage

We use:

  • Signed session cookies after you authenticate
  • An HTTP-only guest cookie (about 30 days) if you enter as a guest
  • A last-viewed-trip cookie so we can reopen the right workspace
  • Browser local storage for theme, layout, selected chat thread, and similar UI state. Without a database, chat can also keep threads locally on the device.
  • Native apps may store the session in the device keychain/secure store and cache trip, chat, and itinerary data in an on-device database so the trip remains usable offline
  • A service worker cache when you install the progressive web app

Analytics, error-monitoring, and payment providers may set their own cookies. You can clear cookies and site data in your browser; that will sign you out.

7. How we share information

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information with:

  • Trip members and observers you invite, as described above
  • OAuth/MCP clients you authorize, limited to the scopes you approve
  • Service providers that run the product: hosting (Vercel), database, cache, private object storage (Amazon S3 and related CDN), public asset storage, email delivery, Stripe, OpenAI and other model providers, Google (sign-in, Maps, Places, directions), Facebook sign-in, Mapbox, OpenStreetMap tiles, Unsplash, weather (Open-Meteo or the configured provider), PostHog, Sentry, and similar vendors
  • Booking and research sites you choose to open from Plan → Book. Those sites receive whatever is in the outbound link; they have their own policies
  • Authorities when required by law, or to protect users and the service

If we are involved in a merger, acquisition, or asset sale, personal information may transfer as part of that transaction under this policy.

8. Retention

We keep account and trip data while your account is open and as needed to provide the service. Short-lived location awareness expires in about 30 minutes. Place, geocode, nearby, and directions caches expire on a schedule. Chat threads may be compacted into a rolling summary while the full transcript remains visible to you in the product.

After account deletion we remove account-owned data as described in section 10. We may retain anonymized event logs, security records, and payment records as required for fraud prevention, accounting, and law.

9. Your choices

  • Location: Buddy → Preferences. Awareness and trip sharing are separate toggles.
  • Buddy memory: Buddy → Memory. You can turn memory off, forget an item, or clear all memories. Memory cannot grant extra permissions.
  • Sharing: change photo, meal, journal, and document visibility from those panels.
  • Connected apps: Settings → Authorized Apps to revoke OAuth grants.
  • Billing: Settings → Billing opens the Stripe customer portal when billing is configured.
  • Emails: tracker enter/leave mail is subscription-based per place; you can unsubscribe there. Sign-in and invitation emails are transactional.
  • Access and correction: most profile and trip data is editable in the app. You can also email hi@mytravelbuddy.ai.

10. Account deletion

Signed-in (non-guest) users can permanently delete their account from Settings → Delete account. That removes the user row and cascaded account-owned data, including trips you created, your Buddy profile and memories, Circle contacts, favorite places, OAuth grants, and files you own.

Deleting a trip you created also deletes that trip for everyone else on it. If you only belong to someone else’s trip, your membership is removed; content you added there may remain with your name detached (for example comments or itinerary items). Internal event logs are anonymized rather than erased.

Guest accounts cannot use in-app deletion; stop using the guest cookie or convert and then delete.

11. Children

The service is for adults. You must be at least 18 to create an account. We do not knowingly collect personal information from children under 13.

You may store information about traveling companions, including minors’ names and birth dates, for planning. You are responsible for having the right to provide that information. Do not use MyTravelBuddy as a child account or to monitor a child without appropriate authority.

12. Security and international processing

We use access controls, private object storage for trip media, hashed OAuth tokens, and authenticated content routes. No method of transmission or storage is completely secure.

We and our providers may process information in the United States and other countries. If you use the service from elsewhere, you understand that your information may be transferred to those locations.

13. Changes

We will update this page when our practices change and revise the “Last updated” date. Material changes may also be noted in the product. Continued use after an update means you accept the revised policy.

14. Contact

Questions about these terms or our privacy practices: email hi@mytravelbuddy.ai or write to MyTravelBuddy at that address.