Privacy Policy

Your data belongs to you.

We keep this simple: we only collect what is needed to plan and manage your trips, we scope every data row to your account, and we give you clear ways to export or delete your information.

Last updated: 9 September 2026

What we collect

We collect only the information needed to run TravelOS for you:

  • Account information — email address, name and profile avatar when you sign up with email/password or an OAuth provider (Google, Microsoft or Apple).
  • Trip details — departure and destination countries/cities, travel dates, budget, dietary preferences, languages, home country, and travel-style preferences you enter into the AI concierge.
  • Documents — passport details, visa records, boarding passes, tickets and receipts you upload to your private document vault.
  • Booking data — flight and hotel confirmation emails you forward, plus the structured trip, boarding-pass and expense records created from them.
  • AI conversations — prompts and responses from the AI Travel Concierge, used to generate itineraries and answer travel questions.
  • Financial data — multi-currency wallet balances, spending records, savings goals, loyalty-program points and payment history processed through Stripe.
  • Notification tokens — browser push-notification endpoints and quiet-hours preferences if you enable alerts.
  • Technical data — browser type, device/IP, error reports and session identifiers needed for security and debugging.

How we use it

Your data is used to operate the service, not to build unrelated profiles:

  • Generate and display your trips, itineraries, budgets, documents and reminders.
  • Send document-expiry, departure, budget and FX alerts you opt into.
  • Process payments and subscriptions through Stripe.
  • Parse booking confirmations so you do not have to type flights and hotels manually.
  • Improve AI relevance within your own account (we do not sell or rent your data).
  • Keep the platform secure, prevent abuse and diagnose errors.

Storage and security

TravelOS runs on a managed cloud backend with row-level security (RLS). In practice this means every database query is scoped to your user ID, so your trips, documents and financial records are only readable or editable by you. Your data is encrypted in transit and at rest by the hosting provider.

Avatars and uploaded documents live in private storage buckets with owner-only access policies. We do not store your payment card details; Stripe handles all card data according to its own security standards.

No system is perfect. If we become aware of a data incident that affects you, we will notify you as quickly as we can and take steps to contain it.

Sharing with third parties

We share data only when it is strictly necessary to deliver a feature:

  • Stripe — for billing, subscriptions and payment history.
  • OAuth providers — Google, Microsoft and Apple only pass through the profile information needed to create your account.
  • AI gateway — trip prompts and booking text are sent to the Lovable AI Gateway for itinerary generation and parsing. This does not include raw payment card or password data.
  • FX and place APIs — anonymised currency and destination lookups may be sent to live-rate and place-information services.

We do not sell your personal data to advertisers or data brokers.

Cookies and analytics

We use essential cookies and local storage to keep you signed in, remember your theme preference and store draft concierge input. We may use basic analytics to understand how the product is used, but we do not use intrusive cross-site trackers or advertising cookies.

Your rights

You can manage your data directly inside TravelOS:

  • Export — download a JSON export of your own records from Settings > Privacy & Security.
  • Delete — permanently delete your account, billing records and travel data from Settings > Danger Zone. This action cannot be undone.
  • Correct — update your profile, trips, documents and preferences at any time.
  • Control notifications — opt in or out of browser push, document, departure, budget and FX alerts in Settings.

For questions or data requests, contact us at privacy@asoultravelos.lovable.app.

Children

TravelOS is not intended for users under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with data, please contact us so we can delete it.

Changes

We may update this policy as TravelOS grows. When we make material changes, we will update the “Last updated” date and, if the change affects how we use your data, notify you through the app or email.

Download your data

Signed-in users can export their own data from Settings > Privacy & Security at any time.

Sign in to TravelOS

Ready to travel with one system?

Join early access and be the first to experience the Travel Operating System.