Privacy policy
Last updated 23 September 2026. This policy is provided in English; the English version is the governing version.
Who we are
Tralvler ("we", "us") is an AI travel planner available at tralvler.com and app.tralvler.com. Tralvler is the data controller for the personal data described in this policy. You can reach the operator at [email protected] for any privacy matter.
What we collect
- Account data — your email address, display name, and a hash of your password (we never store the password itself). If you sign in with Google, we receive your email and profile name from Google.
- Trip content — the preferences you enter (budget, styles, party, pace, cities) and the itineraries generated from them, including your edits, picks and progress.
- Photos — pictures you upload for check-ins. They are stored on our servers and analysed once to verify the check-in.
- Check-in photo metadata — when you upload a photo for a check-in we read the time and, if present, the location embedded in the file to verify the check-in. That metadata is kept with the photo and deleted with it.
- Home zone and weekend zone — the city, and optionally the neighbourhood, you choose for your daily quests, and if you are a member the city you choose for weekends. These are places you name, not a record of where your phone is; we do not track your location.
- Invite cookie — opening someone's invite link sets a "tralvler_ref" cookie for 30 days that remembers whose link it was, so the invitation can be credited if you create an account. It is not used for advertising.
- Feedback answers — what you tell us in the in-app poll, stored with your account so we can act on it.
- Tokens and guides — your token balance, every movement on it, and which place guides you have unlocked.
- Device cookie — a random identifier ("tralvler_did") set in your browser, used to prevent abuse of the free plan and of our paid third-party services. It is not used for advertising.
- Analytics data — product usage events and cookies via PostHog (EU Cloud), used to understand how the product is used. IP addresses are anonymised. This may include session replays of how you interact with our pages; anything you type into input fields is masked and never recorded.
- Marketing cookies — the Meta (Facebook) Pixel, which sets the "_fbp" and "_fbc" cookies to measure whether our ads work. In the EEA, the UK and Switzerland it loads only if you accept the marketing-cookie banner; elsewhere it loads by default and you can switch it off from the notice at the bottom of the page (see "Advertising measurement" below). Your choice itself is stored in a "tralvler.consent.marketing" cookie, and which of the two applies is stored in a "tralvler.consent.region" cookie. If you decline or opt out, none of this is loaded and nothing is sent to Meta.
Advertising measurement (Meta)
To know whether our advertising pays for itself, we measure ad-driven visits and purchases with Meta's tools — but only for visitors whose consent settings allow it, which the next paragraph explains. For those visitors, our servers report checkout and purchase events to Meta Platforms Ireland together with a hashed (unreadable) version of your email address and account id, your IP address, browser information, the Meta cookie ids above, and the purchase amount. Meta uses this to attribute the purchase to an ad and to build campaign statistics. If you declined the banner or opted out, we send Meta nothing — including nothing about your purchases.
Where you are decides how this works. If you are in the EEA, the UK or Switzerland, nothing in this section runs until you accept the marketing-cookie banner — no pixel, no marketing cookies, no server-side events. Everywhere else, the pixel and our server-side measurement run by default from your first visit, and we tell you so in a notice at the bottom of the page: choose "Opt out" there and we stop at once and send Meta nothing further. You can also switch it off at any time by clearing this site's cookies and site data. We work out which of the two applies from your IP address alone, on our own servers, against a country database stored locally — your IP address is not sent anywhere for this, and we do not keep any record of your location. That database is the free IP Geolocation by DB-IP country list, used under its Creative Commons Attribution 4.0 licence.
You can withdraw consent at any time by clearing this site's cookies and site data in your browser (the banner will ask again on your next visit), or by emailing us and we will handle it for you.
Why we process it
We process account and trip data to provide the service you signed up for (contract performance, Art. 6(1)(b) GDPR); the device cookie and related signals to prevent abuse (legitimate interest, Art. 6(1)(f)); billing data to manage subscriptions (contract performance and legal obligations); analytics to improve the product (legitimate interest); and advertising measurement via the Meta Pixel and the server-side events described above with your consent (Art. 6(1)(a)) where you are in the EEA, the UK or Switzerland, and otherwise under the notice-and-opt-out standard of your own country's law. Either way you can turn it off at any time.
Who processes it for us
- Hetzner (Germany) — hosting; your data is stored on servers in the EU.
- Cloudflare — content delivery network and traffic protection in front of our servers.
- OpenRouter — AI generation. Your trip preferences, itinerary context and the facts we hold about a place are sent as prompts to large-language-model providers to generate and verify itineraries and to write place guides. We do not send your email or account identity with these prompts.
- Google Cloud Text-to-Speech (EU endpoint) and, as an alternative, Microsoft Azure Speech (West Europe) — narration of place guides. The guide text is sent to be read aloud; no account data goes with it. The audio is stored on our servers and served to every traveller who unlocks that guide.
- Google Maps Platform — place lookups, routes, place photos and the place facts used in guides.
- Stripe — payment processing for tickets, memberships and token packs, with Stripe's merchant-of-record service (Link, LLC) as the seller of record. We never see or store your card details.
- Resend — sending our email, from sign-in and trip notices to announcements. It receives your email address and name and the content of the message.
- PostHog (EU Cloud) — product analytics and session replay, including analytics cookies. IP addresses are anonymised and typed input is masked in replays.
- Meta Platforms Ireland — advertising measurement, only if you consented to marketing cookies. For the measurement events described above, Meta acts as an independent or joint controller under its own privacy policy.
How long we keep it
Account and trip data are kept while your account exists. Photos are kept until you delete the memory they belong to or your account. Abuse-prevention signals are stored in pseudonymised form (hashed) and expire from our counters over time.
When you delete your account we erase your data. We retain one anonymised code derived from your email address for up to 24 months, solely to prevent a deleted account from being reused to claim another free trip. We do this under Article 6(1)(f) GDPR — our legitimate interest in preventing misuse, as described in Recital 47 — and the code can neither be turned back into your address nor used for anything else; it is deleted automatically on schedule.
Place guides and their narrations describe places, not people, and are kept as shared content after you delete your account. Your token ledger, your unlocked guides, your zones, your feedback answers and the record of who invited you are erased with your account; the person who invited you keeps only a count of invited friends. The invite cookie expires after 30 days.
Your rights
Under the GDPR you can request access to, correction of, or deletion of your personal data, object to processing based on legitimate interest, and request data portability. Email [email protected] and we will act on your request. You also have the right to lodge a complaint with your local supervisory authority.
Changes
If this policy changes materially we will update this page and the date above. The current version always lives at tralvler.com/privacy.