Privacy Policy
Last updated July 10, 2026. Plain language on purpose.
The short version
TripTidy turns travel confirmation emails into organized trips. To do that we read travel-related email you give us access to, keep the structured details (flight numbers, times, confirmation codes), and leave everything else alone. We never train AI models on your email, and neither do our AI providers. You can disconnect your inbox or delete everything with one tap.
What we collect
- Account details — your name and email address from Google or Apple sign-in.
- Travel emails — if you connect Gmail (read-only) or forward mail to your TripTidy address, we process new messages to find bookings. Non-travel mail is discarded at a classification step and is not stored.
- Structured trip data — the itinerary items extracted from those emails (flights, stays, reservations, times, places, confirmation codes).
- Device tokens — so we can send you notifications about your own trips (gate changes, delays).
What we never do
- Train AI models on your email or trip data — ours or anyone’s.
- Sell or share your data with advertisers or data brokers.
- Read email beyond what’s needed to find travel confirmations.
How processing works
Email content is processed by our AI provider (Anthropic) to extract booking details, under terms that prohibit training on your data. Our infrastructure runs on Vercel and Supabase; emails you forward to your TripTidy address are received by Resend and passed to the same pipeline. Gmail access uses Google’s official APIs with the read-only gmail.readonly scope — the data accessed is email message content and headers, used solely to identify and extract travel bookings — revocable any time at myaccount.google.com/permissions.
Product analytics
We measure how TripTidy is used — screens like the trip list, events like “connected an inbox” — via PostHog (US-hosted), tied to your account so we can debug your specific issue when you write in. We never send email content, trip details, or locations to analytics, there are no ads and no cross-app tracking, and the website uses cookieless analytics (nothing is stored on your device).
Google API Limited Use disclosure
TripTidy’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The full Google-scoped disclosure lives at google-api-disclosure.
Retention & deletion
We keep structured trip items so your trips work; raw email content is retained only as long as needed to (re)parse it. Deleting your account (in the app: Settings → Delete all my data, or email us) removes your account, trips, connected inboxes, and stored tokens immediately. Step-by-step instructions: data deletion.
Your rights
Wherever you are, you can ask us what we hold about you, have it corrected, receive a copy of it, or have it deleted — email privacy@triptidy.app and we'll respond within 30 days (deletion is usually same-day; see data deletion). If you're in the UK or EU, these are your GDPR rights and you can also complain to your local data-protection authority — though we'd appreciate the chance to fix things first.
Children
TripTidy is not directed at children under 16, and we don't knowingly collect their data. If you believe a child has created an account, email us and we'll delete it.
Contact
Questions or deletion requests: privacy@triptidy.app.