Privacy Policy
Effective 9 October 2026 · Version 2026.6
1. Who we are
1.1 Plantripr ("Plantripr", "we", "us") runs plantripr.com, an AI travel-itinerary service operated from London, United Kingdom. We are the controller of your personal data under the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR) and, for people in the European Economic Area, the EU GDPR.
1.2 Contact us about privacy at support@plantripr.com. This policy also explains how we use cookies and should be read with our Terms of Service.
2. The personal data we collect
- What it includes
- Email address, username, display name, profile and cover photo, account ID, sign-in method (email or Google). Optional: first and last name, date of birth, phone number, bio, website, preferences (language, currency, units, dietary needs)
- Where it comes from
- You, or Google if you sign in with Google
- What it includes
- A random guest ID our server gives your browser after the bot check, and how many guest trips it has generated
- Where it comes from
- Our systems, stored in your browser
- What it includes
- Destinations, dates, trip length, travellers, budget, pace, style tags, dietary notes, your prompts, the itineraries we generate, search history, favourite places, visited places and achievements.
- Where it comes from
- You and our AI
- What it includes
- Your messages to Tripr AI and its replies, the places, events and tours it found for you, changes it proposed and whether you accepted them, the support requests it drafted, and (for long chats) a short summary of the older messages
- Where it comes from
- You and our AI
- What it includes
- What you asked Tripr AI to keep in mind about you or a trip: diet, allergies, kinds of place you avoid, pace, travelling with children, things you like or dislike, short notes
- Where it comes from
- You, with your approval
- What it includes
- Your device's approximate position (rounded to about 100 m), used for that one search
- Where it comes from
- Your device, with your permission
- What it includes
- Public profile, trips and travel guides you publish (including images), followers, likes, comments, reports, trips you unlock and trips others unlock from you, people you share a trip with, and their votes and notes
- Where it comes from
- You and other users
- What it includes
- Your plan (Guest, Free, Trial, Premium), monthly allowance used, credit purchases, bonus and creator-reward credits, what credits were spent on, balances and expiry dates
- Where it comes from
- Our systems
- What it includes
- Your email address in a normalised form (for Gmail, dots and +tags removed) and a scrambled (hashed) form of a random device ID from your browser
- Where it comes from
- You and your browser
- What it includes
- Stripe customer ID, subscription status, amounts, currency, dates, card type and last four digits. We never see or store your full card number or security code
- Where it comes from
- Stripe
- What it includes
- What you agreed to at checkout and when, cancellation and withdrawal requests (name, email, which purchase, date and time) and the service emails we sent you
- Where it comes from
- You and our systems
- What it includes
- The country your IP address belongs to, used to show prices in pounds, euros or dollars (not stored), and the currency of your first purchase (stored)
- Where it comes from
- Your IP address, via ipinfo
- What it includes
- Event times, titles and locations, read only, processed and kept in your browser (section 6)
- Where it comes from
- Google, with your permission
- What it includes
- IP address (kept by us only as a salted hash for rate limits; our hosting providers keep raw request logs, including IP addresses, for a few days for security), browser and device type, language, error logs, bot-check results
- Where it comes from
- Your device, Cloudflare
- What it includes
- With your consent: pages viewed, features used, approximate location, device details, and PostHog session replays (typed text hidden, IP addresses anonymised). If you decline: anonymous cookie-free counts only. Also anonymous monthly counts of what people do with places in plans (kept, swapped, removed, favourited, booked), never linked to an account or a trip
- Where it comes from
- Google Analytics, PostHog; Plantripr (anonymous counts)
- What it includes
- Emails and requests you send us
- Where it comes from
- You
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Email address, username, display name, profile and cover photo, account ID, sign-in method (email or Google). Optional: first and last name, date of birth, phone number, bio, website, preferences (language, currency, units, dietary needs) | You, or Google if you sign in with Google |
| Guest identifier | A random guest ID our server gives your browser after the bot check, and how many guest trips it has generated | Our systems, stored in your browser |
| Trip planning and saved content | Destinations, dates, trip length, travellers, budget, pace, style tags, dietary notes, your prompts, the itineraries we generate, search history, favourite places, visited places and achievements. | You and our AI |
| Tripr AI chats | Your messages to Tripr AI and its replies, the places, events and tours it found for you, changes it proposed and whether you accepted them, the support requests it drafted, and (for long chats) a short summary of the older messages | You and our AI |
| Tripr AI memory (only if you turn it on) | What you asked Tripr AI to keep in mind about you or a trip: diet, allergies, kinds of place you avoid, pace, travelling with children, things you like or dislike, short notes | You, with your approval |
| Location for "Near me" (only when you tap it) | Your device's approximate position (rounded to about 100 m), used for that one search | Your device, with your permission |
| Public profile, community and sharing | Public profile, trips and travel guides you publish (including images), followers, likes, comments, reports, trips you unlock and trips others unlock from you, people you share a trip with, and their votes and notes | You and other users |
| Plan, credits and usage | Your plan (Guest, Free, Trial, Premium), monthly allowance used, credit purchases, bonus and creator-reward credits, what credits were spent on, balances and expiry dates | Our systems |
| Free-trial record | Your email address in a normalised form (for Gmail, dots and +tags removed) and a scrambled (hashed) form of a random device ID from your browser | You and your browser |
| Payments | Stripe customer ID, subscription status, amounts, currency, dates, card type and last four digits. We never see or store your full card number or security code | Stripe |
| Purchase and contract records | What you agreed to at checkout and when, cancellation and withdrawal requests (name, email, which purchase, date and time) and the service emails we sent you | You and our systems |
| Country for pricing | The country your IP address belongs to, used to show prices in pounds, euros or dollars (not stored), and the currency of your first purchase (stored) | Your IP address, via ipinfo |
| Google Calendar (optional) | Event times, titles and locations, read only, processed and kept in your browser (section 6) | Google, with your permission |
| Technical and security | IP address (kept by us only as a salted hash for rate limits; our hosting providers keep raw request logs, including IP addresses, for a few days for security), browser and device type, language, error logs, bot-check results | Your device, Cloudflare |
| Analytics | With your consent: pages viewed, features used, approximate location, device details, and PostHog session replays (typed text hidden, IP addresses anonymised). If you decline: anonymous cookie-free counts only. Also anonymous monthly counts of what people do with places in plans (kept, swapped, removed, favourited, booked), never linked to an account or a trip | Google Analytics, PostHog; Plantripr (anonymous counts) |
| Support | Emails and requests you send us | You |
Please don't put sensitive information (for example about health or religion) into trip prompts unless you want it used for that trip. We don't need it and don't use it for anything else.
Diet and allergy details you give Tripr AI can be health information. Tripr AI keeps them in its memory only after you have turned memory on (one approval, which you can withdraw at any time in the Tripr AI panel or in Settings → Preferences), and uses them only to make its suggestions fit you.
3. Why we use it and our lawful basis
- Data used
- Account
- Lawful basis
- Contract
- Data used
- Trip planning, account, sharing
- Lawful basis
- Contract
- Data used
- Tripr AI chats, trip planning, account (plan and allowance)
- Lawful basis
- Contract
- Data used
- Tripr AI memory
- Lawful basis
- Consent (explicit consent for health details such as allergies); you can withdraw it at any time
- Data used
- Location for "Near me"
- Lawful basis
- Consent (your device asks each time)
- Data used
- Plan, credits and usage; guest identifier
- Lawful basis
- Contract; for guests, legitimate interests (fair use)
- Data used
- Plan, credits and usage
- Lawful basis
- Contract
- Data used
- Free-trial record
- Lawful basis
- Legitimate interests (preventing abuse of a free offer)
- Data used
- Public profile and community
- Lawful basis
- Contract
- Data used
- Country for pricing
- Lawful basis
- Legitimate interests
- Data used
- Payments, plan and credits
- Lawful basis
- Contract; legal obligation (tax and accounting)
- Data used
- Purchase and contract records
- Lawful basis
- Legal obligation (consumer law); legitimate interests (proving what happened)
- Data used
- Account, payments
- Lawful basis
- Contract; legal obligation
- Data used
- Google Calendar
- Lawful basis
- Consent (you connect it and can disconnect at any time)
- Data used
- Technical and security, guest identifier
- Lawful basis
- Legitimate interests
- Data used
- Analytics
- Lawful basis
- Consent; for anonymous cookie-free counts when you decline, legitimate interests
- Data used
- Outbound link parameters
- Lawful basis
- Legitimate interests
- Data used
- Any relevant data
- Lawful basis
- Legitimate interests; legal obligation
| Purpose | Data used | Lawful basis |
|---|---|---|
| Create and run your account | Account | Contract |
| Generate, save, edit and share itineraries | Trip planning, account, sharing | Contract |
| Answer your Tripr AI messages, find real places, events and tours, propose changes to your trips, and draft support requests | Tripr AI chats, trip planning, account (plan and allowance) | Contract |
| Remember your preferences across chats and pre-fill the trip form | Tripr AI memory | Consent (explicit consent for health details such as allergies); you can withdraw it at any time |
| Find places near you | Location for "Near me" | Consent (your device asks each time) |
| Apply plan limits and credits | Plan, credits and usage; guest identifier | Contract; for guests, legitimate interests (fair use) |
| Count daily messages and searches, and charge credits only after you tap a button that shows the price | Plan, credits and usage | Contract |
| Allow the free trial once per person | Free-trial record | Legitimate interests (preventing abuse of a free offer) |
| Run public profiles, publishing, likes, comments, reports and unlocks | Public profile and community | Contract |
| Show prices in your currency and stop people paying a cheaper regional price | Country for pricing | Legitimate interests |
| Take payments, give refunds, keep accounts | Payments, plan and credits | Contract; legal obligation (tax and accounting) |
| Record what you agreed at checkout and your cancellation or withdrawal requests | Purchase and contract records | Legal obligation (consumer law); legitimate interests (proving what happened) |
| Send service emails (order confirmations, renewal reminders, cancellations, refunds) | Account, payments | Contract; legal obligation |
| Show Google Calendar conflicts | Google Calendar | Consent (you connect it and can disconnect at any time) |
| Keep the service secure and stop bots, fraud and abuse | Technical and security, guest identifier | Legitimate interests |
| Measure and improve the site | Analytics | Consent; for anonymous cookie-free counts when you decline, legitimate interests |
| Track affiliate referrals | Outbound link parameters | Legitimate interests |
| Handle complaints, disputes and legal claims | Any relevant data | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have weighed them against your rights. You can object (section 11).
4. Guests
4.1 You can try Plantripr without an account. Guests can generate 1 one-day trip in total. After a quick bot check, our server gives your browser a random guest ID and counts the trips made with it. The ID doesn't contain your name or email.
4.2 To stop the limit being bypassed by clearing the browser, we also limit guest trips to 10 a day per internet connection. For this we keep your IP address only in a scrambled (salted hash) form.
4.3 If you create an account, trips you saved as a guest on that device are moved into it.
5. AI processing
5.1 We use two AI providers. Google's Gemini models generate itineraries from the trip form. Anthropic's Claude models power Tripr AI, our chat concierge, including trips planned in the chat. We send each provider only what's needed: your messages, trip details and the relevant itinerary, and for Tripr AI also what it remembers about you (if memory is on) and the booking text, screenshot or PDF you choose to share. We never send your password or payment details, and Claude is never sent your location: for "Near me" our server uses your location for that one search and only tells Claude that a location was shared.
5.2 We use the paid Gemini API and Anthropic's commercial API. Under their terms, neither Google nor Anthropic uses our requests to train their models.
5.3 Itineraries are suggestions. We don't make decisions about you by automated means that have legal or similarly significant effects (Article 22 GDPR).
5.4 When you ask Tripr AI what's trending, it searches the web through Anthropic's web search. Only the topic and the city are searched, never your name or account details. The answer shows the websites it comes from; those results are not checked by Plantripr.
5.5 When you use "Add my booking", the text, screenshot, PDF or email you choose is sent once to Claude to read the flight, train or hotel details. We don't store the file or its text; only the booking card you accept is saved in your trip.
5.6 In long planner chats, Tripr AI writes a short summary of the older messages so it can keep following the conversation. You still see every message; the summary is kept with the chat and deleted with it.
6. Google user data (Google Calendar)
6.1 Plantripr's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
6.2 If you connect Google Calendar, we ask for read-only access (calendar.events.readonly). We use it only to show your events next to your itinerary and point out clashes.
6.3 Calendar data and the Google access token are processed and kept in your browser's storage on your device until you disconnect. We don't store calendar events or Google access tokens on our servers, don't use them for advertising, don't sell or transfer them, and don't use them to train AI models.
6.4 You can disconnect in Plantripr's calendar settings or at myaccount.google.com/permissions.
8. Partner links
8.1 Some links are affiliate links to Viator, GetYourGuide and Travelpayouts. When you click one, the partner learns which site sent you, so we can be paid a commission if you book. We don't send them your name or email.
8.2 Other links, such as OpenTable, Ticketmaster, Trainline or Rentalcars, are ordinary links and we earn nothing from them. Once you leave Plantripr, the other site's privacy policy applies.
10. How long we keep data
- How long
- While your account is open
- How long
- Deactivated and restorable for 30 days, then deleted or anonymised
- How long
- 6 years after the end of the financial year they relate to
- How long
- While your account is open, then as for closed accounts; records tied to a payment are kept with payment records
- How long
- Until you delete the chat or close your account
- How long
- 30 days after the last message, unless you sign up and they move to your account
- How long
- Until you remove an item, turn memory off and clear it, or close your account; a trip's memory is deleted with the trip
- How long
- Not stored (read once)
- How long
- Not stored (used for one search)
- How long
- 120 days
- How long
- 3 years after the trial, to stop repeat trials
- How long
- In your browser until you clear it; our trip count for 12 months
- How long
- 2 years
- How long
- Google Analytics up to 14 months; PostHog session replays 30 days, other PostHog data up to 1 year
- How long
- Up to 400 days (monthly counts that can't identify you)
- How long
- 2 years
- How long
- 30 days
| Data | How long |
|---|---|
| Account, trips and saved content | While your account is open |
| Closed accounts | Deactivated and restorable for 30 days, then deleted or anonymised |
| Invoices, payment records, checkout consents, cancellation and withdrawal records | 6 years after the end of the financial year they relate to |
| Credit and usage records | While your account is open, then as for closed accounts; records tied to a payment are kept with payment records |
| Tripr AI chats (signed in) | Until you delete the chat or close your account |
| Tripr AI chats (guests) | 30 days after the last message, unless you sign up and they move to your account |
| Tripr AI memory | Until you remove an item, turn memory off and clear it, or close your account; a trip's memory is deleted with the trip |
| Booking files you share with Tripr AI | Not stored (read once) |
| Location for "Near me" | Not stored (used for one search) |
| Daily message and search counts | 120 days |
| Free-trial record | 3 years after the trial, to stop repeat trials |
| Guest identifier | In your browser until you clear it; our trip count for 12 months |
| Service email log | 2 years |
| Analytics | Google Analytics up to 14 months; PostHog session replays 30 days, other PostHog data up to 1 year |
| Anonymous place statistics | Up to 400 days (monthly counts that can't identify you) |
| Support emails | 2 years |
| Security and rate-limit records (hashed IP) | 30 days |
Anonymised data can't identify you and may be kept for statistics.
11. Your rights
You have the right to: access your data; correct it; have it erased; restrict how we use it; object to uses based on legitimate interests; receive your data in a portable format; and withdraw consent at any time (this doesn't affect what we did before).
Email support@plantripr.com to use these rights. We'll reply within one month and may ask you to prove who you are. You can also complain to the UK Information Commissioner's Office (ico.org.uk) or the data protection authority where you live in the EEA. Please contact us first so we can try to help.
12. Deleting your account
12.1 You can close your account by emailing support@plantripr.com. It is deactivated straight away and can be restored for 30 days. After 30 days we delete or anonymise your data, except payment and contract records we must keep for 6 years. Your Tripr AI chats and memory are deleted with your account.
12.2 Trips and guides you published are removed from public view when your account is deactivated. Copies that other users unlocked belong to their accounts and stay there. Your comments are deleted with your account.
13. International transfers
Our database is hosted in London (UK) and our email provider sends from the EU. Some providers (including Google, Stripe, Cloudflare and ipinfo) process data outside the UK and EEA, including in the United States. We protect these transfers with adequacy regulations or decisions (including the UK Extension and the EU–US Data Privacy Framework where the provider is certified), or with standard contractual clauses and the UK International Data Transfer Addendum.
14. Security
We use HTTPS encryption, encryption at rest by our database provider, access controls and bot protection. No online service is perfectly secure; if a breach puts you at risk, we'll tell you and the regulator as the law requires.
15. Age limit
Plantripr is for people aged 18 or over. When you sign up you confirm you are 18 or over. If we learn an account belongs to someone under 18, we'll close it and delete its data.
16. Changes to this policy
We'll post changes here with a new effective date. If a change materially affects you, we'll email you before it applies.
17. Contact
Plantripr, London, United Kingdom · support@plantripr.com