Privacy Policy

Last updated: August 2026

Intelligent Travel Guide (“we”, “the app”) is an AI-powered travel companion. This policy explains what data we collect, why, and how you can control it.

Data we collect

  • Account data: your email address (and name if you provide it) when you register or sign in, managed securely by our authentication platform.
  • Your content: saved favourites, notes and itineraries you create. These are private to your account — no other user can see or modify them.
  • Chat & photos: messages and images you send to the AI guide to get recommendations. These are processed to answer your request; discovered places from your queries are linked to your account and visible only to you and administrators.
  • Location: your device location is used only on your device to provide nearby recommendations. Coordinates are not permanently stored, are rounded before being shared with our AI provider, and are never visible to other users.
  • Usage data: anonymous analytics events (e.g. “search performed”) to improve the app.

How we use it

  • To provide, personalize and improve travel guidance.
  • To save your favourites and itineraries and show them back to you.
  • To authenticate you and protect your account from abuse.

Sharing

We do not sell your data. Location and chat context are sent only to our AI provider as needed to answer your question. Map and address lookups use a public geocoding service. Administrative destination data is curated by administrators and publicly readable; your personal data is never exposed through public pages, URLs or APIs.

Your rights

  • Access, export or correct your personal data.
  • Request deletion of your account and associated data (favourites, itineraries, notes and discovered places).
  • Withdraw geolocation permission at any time through your browser settings.

To exercise these rights, contact the app owner through your account or the support channel provided at deployment. Deletion requests cover the data this application stores; the underlying platform account can be removed by the workspace administrator.

Security

Access to data is enforced server-side per-user. Administrative functions require an administrator role. User input is validated, and AI output is rendered as plain text to prevent cross-site scripting.

This is a summary policy. For legal commitments, consult the Terms of Service and your local privacy authority.