← triptidy.app

How TripTidy uses Google user data

This page describes TripTidy's use of data received via Google APIs. It supplements the privacy policy, which governs everything we do.

What we request

One scope: https://www.googleapis.com/auth/gmail.readonly — read-only access to Gmail. We also receive your name and email address at sign-in. TripTidy cannot send, modify, delete, or label email.

How we access and use it

TripTidy reads new and (when you request a scan) past email messages for a single purpose: identifying travel bookings and turning them into your itinerary. A classification step discards non-travel mail; travel confirmations are processed to extract structured booking details — flights, stays, reservations, times, places, confirmation codes — which power your trips, notifications, and calendar feed.

What we store

The structured booking details above, and your Gmail refresh token (encrypted at rest) so syncing works. Raw email content is retained only as long as needed to (re)parse it. Non-travel email is never stored.

What we share

Google user data is never sold, never used for advertising, and never transferred to data brokers. Email content is processed by Anthropic (our AI extraction provider) under terms prohibiting training on your data; our infrastructure runs on Vercel and Supabase. No human reads your email except with your explicit permission for support, for security purposes, or where required by law.

Limited Use disclosure

TripTidy's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Your controls

Revoke TripTidy's access any time at myaccount.google.com/permissions, disconnect your inbox in the app (Settings → Inboxes), or delete everything we hold — see data deletion.